RoguePlanet CVE-2026-50656: Microsoft Defender SYSTEM Privilege Escalation Patched
July 10, 2026 Microsoft has finally released a security update for the RoguePlanet CVE-2026-50656 vulnerability. This flaw allowed local attackers to escalate privileges to SYSTEM level through a race condition in the Microsoft Malware Protection Engine.…
Injective SDK npm Supply Chain Attack: Crypto Wallet Keys Stolen via Compromised Package
July 9, 2026 Threat actors compromised a legitimate GitHub contributor account for the Injective Labs SDK project and published a malicious npm package that steals cryptocurrency wallet private keys and mnemonic seed phrases. The attack affected version…
Seven FatFs Vulnerabilities Expose Millions of Embedded Devices to Memory Corruption and Code Execution
July 4, 2026 Security researchers at runZero have disclosed seven vulnerabilities in FatFs, a small filesystem library used by millions of embedded devices worldwide. Consequently, any device that reads FAT or exFAT storage — including security cameras,…
Bad Epoll CVE-2026-46242: Linux Kernel Privilege Escalation Hits Android
July 3, 2026 A newly disclosed Linux kernel vulnerability dubbed “Bad Epoll” (CVE-2026-46242) allows an unprivileged user to escalate to root on Linux desktops, servers, and Android devices. The flaw is a use-after-free in the kernel’s…
Adobe ColdFusion Critical Patch: 6 CVSS 10.0 RCE Flaws Disclosed
July 2, 2026 Adobe has released urgent security patches for ColdFusion, resolving multiple critical vulnerabilities including six rated at the maximum CVSS score of 10.0. These flaws enable unauthenticated remote code execution on widely deployed…
SharePoint RCE CVE-2026-45659: CISA KEV Alert After Active Exploitation
July 2, 2026 CISA has confirmed active exploitation of a high-severity Microsoft SharePoint remote code execution vulnerability tracked as CVE-2026-45659 (CVSS: 8.8). Organizations running supported SharePoint Server versions should patch immediately to…
Cursor DuneSlide CVEs Enable Zero-Click Prompt Injection RCE on Developer Machines
July 01, 2026 Two critical vulnerabilities in the Cursor AI code editor enable zero-click prompt injection attacks that break out of the IDE’s security sandbox and run arbitrary commands on a developer’s machine. Discovered by Cato AI Labs…
Langflow CVE Critical RCE Deploys Monero Miner on AI Endpoints
June 30, 2026 On June 30, 2026, Trend Micro published a technical report confirming that threat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow. The flaw carries a CVSS score of…
BlueHammer CVE: Ransomware Gangs Actively Exploit Microsoft Defender Privilege Escalation Flaw
June 30, 2026 CISA confirmed on Monday that ransomware gangs are now actively exploiting a high-severity Microsoft Defender privilege escalation vulnerability known as BlueHammer. The flaw, tracked as CVE-2026-33825, was originally leaked as a zero-day…
macOS ClickFix Attack Silently Deploys AMOS Infostealer via Fake CAPTCHA Terminal Commands
June 28, 2026 Security researchers at Palo Alto Networks Unit 42 have uncovered a new macOS ClickFix campaign that uses Terminal commands to silently download, mount, and execute infostealing malware. The campaign targets Mac users with fake CAPTCHA…