TrojPix Attack Exfiltrates Data From Air-Gapped Systems via Video Cables
July 6, 2026 Researchers at Shandong University have unveiled TrojPix, a novel attack that leaks data from air-gapped systems by modulating video cable electromagnetic emissions. The technique achieves a peak throughput of 8.1 Mbps and reaches distances…
NetNut Botnet Disrupted: FBI and Google Cut Off 2 Million Compromised Devices
July 5, 2026 A coordinated operation involving Google, the FBI, and industry partners has disrupted NetNut, one of the largest residential proxy networks in the world. The botnet, also known as Popa, compromised at least 2 million Android devices…
Seven FatFs Vulnerabilities Expose Millions of Embedded Devices to Memory Corruption and Code Execution
July 4, 2026 Security researchers at runZero have disclosed seven vulnerabilities in FatFs, a small filesystem library used by millions of embedded devices worldwide. Consequently, any device that reads FAT or exFAT storage — including security cameras,…
Bad Epoll CVE-2026-46242: Linux Kernel Privilege Escalation Hits Android
July 3, 2026 A newly disclosed Linux kernel vulnerability dubbed “Bad Epoll” (CVE-2026-46242) allows an unprivileged user to escalate to root on Linux desktops, servers, and Android devices. The flaw is a use-after-free in the kernel’s…
Adobe ColdFusion Critical Patch: 6 CVSS 10.0 RCE Flaws Disclosed
July 2, 2026 Adobe has released urgent security patches for ColdFusion, resolving multiple critical vulnerabilities including six rated at the maximum CVSS score of 10.0. These flaws enable unauthenticated remote code execution on widely deployed…
SharePoint RCE CVE-2026-45659: CISA KEV Alert After Active Exploitation
July 2, 2026 CISA has confirmed active exploitation of a high-severity Microsoft SharePoint remote code execution vulnerability tracked as CVE-2026-45659 (CVSS: 8.8). Organizations running supported SharePoint Server versions should patch immediately to…
Cursor DuneSlide CVEs Enable Zero-Click Prompt Injection RCE on Developer Machines
July 01, 2026 Two critical vulnerabilities in the Cursor AI code editor enable zero-click prompt injection attacks that break out of the IDE’s security sandbox and run arbitrary commands on a developer’s machine. Discovered by Cato AI Labs…
Aflac Japan Data Breach Exposes 4.38 Million Customer Records
July 1, 2026 American insurance giant Aflac disclosed a major data breach after attackers compromised its Japan subsidiary and stole personal and bank account information of 4.38 million customers. The incident, discovered on June 25, 2026, represents…
Langflow CVE Critical RCE Deploys Monero Miner on AI Endpoints
June 30, 2026 On June 30, 2026, Trend Micro published a technical report confirming that threat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow. The flaw carries a CVSS score of…
RustDuck Botnet Rebuilds Core in Rust for DDoS Attacks on Routers and Servers
June 30, 2026 A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers to build a distributed denial-of-service (DDoS) botnet. Researchers at QiAnXin’s XLab have tracked it…