Critical Progress LoadMaster CVE Enables Unauthenticated Command Injection
August 11, 2026 CISA has added CVE-2026-8037, a critical command injection vulnerability in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities Catalog. Attackers are actively exploiting this flaw to execute arbitrary commands on unpatched…
Head Mare Hacktivists Trojanize TrueConf Installers to Deploy PhantomCore and PhantomGraph Backdoors
August 10, 2026 The Head Mare hacktivist group has been exploiting unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions that deliver backdoors. Researchers at Kaspersky discovered the campaign in…
SCTPhantom Linux Kernel Flaw: 18-Year-Old SCTP Bug Enables Root and Container Escape
August 9, 2026 Researchers at Tencent Zhuque Lab disclosed an 18-year-old Linux kernel vulnerability in the Stream Control Transmission Protocol (SCTP) that could allow a local attacker to gain root privileges and escape container boundaries. Tracked as…
Critical Rails Active Storage Flaw Exposes Server Secrets
July 29, 2026 A critical vulnerability in Ruby on Rails Active Storage could let unauthenticated attackers read arbitrary files from application servers using crafted image uploads. Tracked as CVE-2026-66066 with a CVSS score of 9.5, the flaw exposes…
Browser Assembled Malware Targets Crypto Traders and Investors
July 27, 2026 A massive malvertising operation dubbed SourTrade is using fake cryptocurrency and trading websites to turn victims’ browsers into local malware assembly lines. Threat actors leverage JavaScript, service workers, and a clean copy of…
Hotel Wi-Fi DNS Hijack Campaign Steals Microsoft 365 Accounts
July 26, 2026 Threat actors are hijacking hotel and conference center Wi-Fi gateways to redirect business travelers to fake Microsoft 365 login pages. The campaign, active since at least June 2026, uses DNS manipulation and device-code authentication to…
Hermes AI Agent Automates Post-Exploitation Inside Thailand Ministry of Finance
July 24, 2026 A threat actor deployed the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation inside Thailand’s Ministry of Finance. The operation was uncovered after the attacker left 585 files and 470…
Critical Fastjson RCE Under Active Exploitation
July 25, 2026 Security researchers have uncovered a critical remote code execution flaw in Alibaba’s Fastjson 1.x library. Tracked as CVE-2026-16723, this vulnerability carries a CVSS score of 9.0 and is already under active exploitation in the…
XBOW Bing Images RCE: SVG Command Injection Yields SYSTEM Shells
July 24, 2026 XBOW, an autonomous offensive security startup, disclosed two critical remote code execution vulnerabilities in Microsoft Bing’s image processing pipeline. The flaws, tracked as CVE-2026-32194 and CVE-2026-32191, both carry a CVSS…
SharePoint CVE-2026-50522: Critical RCE Under Active Exploitation to Steal Machine Keys
July 22, 2026 Microsoft SharePoint administrators are racing to patch a critical remote code execution vulnerability that attackers are actively exploiting in the wild. The flaw, tracked as CVE-2026-50522, allows unauthenticated remote code execution…