CISA KEV Alert for Active Zero-Day Exploitation of Cisco FMC
July 30, 2026 CISA has added a newly disclosed Cisco Secure Firewall Management Center zero-day to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The vulnerability, tracked as CVE-2026-20316, allows…
Browser Assembled Malware Targets Crypto Traders and Investors
July 27, 2026 A massive malvertising operation dubbed SourTrade is using fake cryptocurrency and trading websites to turn victims’ browsers into local malware assembly lines. Threat actors leverage JavaScript, service workers, and a clean copy of…
Hotel Wi-Fi DNS Hijack Campaign Steals Microsoft 365 Accounts
July 26, 2026 Threat actors are hijacking hotel and conference center Wi-Fi gateways to redirect business travelers to fake Microsoft 365 login pages. The campaign, active since at least June 2026, uses DNS manipulation and device-code authentication to…
Hermes AI Agent Automates Post-Exploitation Inside Thailand Ministry of Finance
July 24, 2026 A threat actor deployed the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation inside Thailand’s Ministry of Finance. The operation was uncovered after the attacker left 585 files and 470…
Critical Fastjson RCE Under Active Exploitation
July 25, 2026 Security researchers have uncovered a critical remote code execution flaw in Alibaba’s Fastjson 1.x library. Tracked as CVE-2026-16723, this vulnerability carries a CVSS score of 9.0 and is already under active exploitation in the…
RefluXFS CVE: Nine-Year-Old Linux Kernel Flaw Grants Root
July 23, 2026 A nine-year-old race condition in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on disk and gain persistent root access. The flaw, dubbed RefluXFS by Qualys,…
Hugging Face AI Agent Breach
July 20, 2026 Hugging Face, the world’s largest open-source artificial intelligence platform, disclosed that attackers breached its production infrastructure using an autonomous AI agent system. The intrusion marks one of the first confirmed cases…
HelloNet APT Campaign Abuses ViPNet Update System
July 20, 2026 An advanced threat actor is abusing the update mechanism of ViPNet, a Russian-certified private networking suite, to implant persistent backdoors in government agencies and critical infrastructure across Russia. Dubbed HelloNet by Kaspersky…
Abbott Laboratories Double Cyber Incident: ShinyHunters Claims PII Records Stolen in Vishing Attack
July 19, 2026 Abbott Laboratories, one of the world’s largest medical technology companies, is investigating two separate cybersecurity incidents disclosed this week. One involves the ShinyHunters extortion gang, which claims to have stolen more than 30…
TrojPix Attack Exfiltrates Data From Air-Gapped Systems via Video Cables
July 6, 2026 Researchers at Shandong University have unveiled TrojPix, a novel attack that leaks data from air-gapped systems by modulating video cable electromagnetic emissions. The technique achieves a peak throughput of 8.1 Mbps and reaches distances…