Seven FatFs Vulnerabilities Expose Millions of Embedded Devices to Memory Corruption and Code Execution
July 4, 2026 Security researchers at runZero have disclosed seven vulnerabilities in FatFs, a small filesystem library used by millions of embedded devices worldwide. Consequently, any device that reads FAT or exFAT storage — including security cameras,…
Bad Epoll CVE-2026-46242: Linux Kernel Privilege Escalation Hits Android
July 3, 2026 A newly disclosed Linux kernel vulnerability dubbed “Bad Epoll” (CVE-2026-46242) allows an unprivileged user to escalate to root on Linux desktops, servers, and Android devices. The flaw is a use-after-free in the kernel’s…
Adobe ColdFusion Critical Patch: 6 CVSS 10.0 RCE Flaws Disclosed
July 2, 2026 Adobe has released urgent security patches for ColdFusion, resolving multiple critical vulnerabilities including six rated at the maximum CVSS score of 10.0. These flaws enable unauthenticated remote code execution on widely deployed…
SharePoint RCE CVE-2026-45659: CISA KEV Alert After Active Exploitation
July 2, 2026 CISA has confirmed active exploitation of a high-severity Microsoft SharePoint remote code execution vulnerability tracked as CVE-2026-45659 (CVSS: 8.8). Organizations running supported SharePoint Server versions should patch immediately to…
RustDuck Botnet Rebuilds Core in Rust for DDoS Attacks on Routers and Servers
June 30, 2026 A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers to build a distributed denial-of-service (DDoS) botnet. Researchers at QiAnXin’s XLab have tracked it…
BlueHammer CVE: Ransomware Gangs Actively Exploit Microsoft Defender Privilege Escalation Flaw
June 30, 2026 CISA confirmed on Monday that ransomware gangs are now actively exploiting a high-severity Microsoft Defender privilege escalation vulnerability known as BlueHammer. The flaw, tracked as CVE-2026-33825, was originally leaked as a zero-day…
macOS ClickFix Attack Silently Deploys AMOS Infostealer via Fake CAPTCHA Terminal Commands
June 28, 2026 Security researchers at Palo Alto Networks Unit 42 have uncovered a new macOS ClickFix campaign that uses Terminal commands to silently download, mount, and execute infostealing malware. The campaign targets Mac users with fake CAPTCHA…
Polymarket Supply-Chain Attack Drains Million in Crypto via Frontend Compromise
June 28, 2026 Polymarket, a $9 billion cryptocurrency-based prediction market platform, disclosed on June 26, 2026, that attackers stole approximately $3 million from customers through a frontend supply-chain attack. Consequently, the breach exploited a…
Amazon Q Developer CVE Malicious MCP Configs Steal Cloud Credentials
June 26, 2026 A high-severity vulnerability in Amazon Q Developer could allow malicious repositories to run arbitrary commands and steal a developer’s cloud credentials. The flaw, tracked as CVE-2026-12957 with a CVSS score of 8.5, was disclosed by…
Cisco Unified CM CVE-2026-20230: Active Exploitation Confirmed
June 24, 2026 A critical server-side request forgery vulnerability in Cisco Unified Communications Manager is now under active exploitation in the wild. Threat intelligence firm Defused confirmed attacks against CVE-2026-20230 over the weekend, marking a…