Blog
ShinyHunters Claims EY Data Breach — Client Tax Records, SSNs, and a July 31 Extortion Deadline
ShinyHunters claims EY data breach exposing client SSNs and tax data via supply-chain attack. Extortion deadline is July 31, 2026 — here’s what security teams must do now.
Read More →Three Fortinet FortiSandbox CVEs Are Being Chained for Unauthenticated Root Access — CISA Deadline Passed, Exploitation Confirmed
CVE-2026-25089 (CVSS 9.8), CVE-2026-39808, and CVE-2026-39813 in Fortinet FortiSandbox are being chained by attackers for unauthenticated OS command execution. CISA KEV deadline passed — patch to 4.4.9 or 5.0.6 now.
Read More →CVE-2026-16812 (CVSS 10.0): Arista VeloCloud SD-WAN Orchestrator Zero-Day Is Being Actively Exploited — Patch by July 30
CVE-2026-16812 (CVSS 10.0) is an unauthenticated OS command injection in Arista VeloCloud Orchestrator being actively exploited. CISA KEV deadline is July 30. Patch on-prem VCO now.
Read More →TELESHIM: East Asia APT Abuses Telegram for C2 to Backdoor Government Systems — How Trusted Apps Become Attack Channels
East Asia APT deploys TELESHIM malware using Telegram Bot API for C2 to backdoor government systems. IOCs, technical breakdown, and zero-trust defences.
Read More →CVE-2026-54121 ‘Certighost’: Any Domain User Can Now Steal Your krbtgt — Working PoC Is Public, Patch AD CS Today
CVE-2026-54121 'Certighost' (CVSS 8.8): a public PoC lets any domain user impersonate a DC, run DCSync, and steal krbtgt. All Windows Server 2012-2025 affected. Patch now.
Read More →CVE-2026-16723 (CVSS 9.0): Fastjson 1.x Zero-Day Is Silently Hacking Spring Boot Apps — No Patch, Active Exploitation
CVE-2026-16723 is a CVSS 9.0 RCE in Fastjson 1.x with no patch available. Attackers are actively exploiting Spring Boot fat-JAR apps. Here's what to do right now.
Read More →CVE-2026-16232 (CVSS 9.3): Check Point SmartConsole Zero-Day Lets Attackers Rewrite Your Firewall Policy
CVE-2026-16232 (CVSS 9.3): Check Point SmartConsole zero-day grants full admin access with no credentials. Exploited in wild, CISA KEV listed — patch steps and IOCs inside.
Read More →No CVE, No Alert: GitLab Exploit Lets Any Authenticated User Hijack Your Server
A working GitLab RCE proof-of-concept released July 24 exploits Oj parser memory bugs. Any user with push access can run commands as git. No CVE assigned — patch to 18.11.5…
Read More →CVE-2026-12569 (CVSS 9.3): Cl0p Is Raiding Manufacturing PLM Systems — Patch PTC Windchill and FlexPLM Before Your IP Is Gone
Cl0p ransomware affiliates are exploiting CVE-2026-12569 (CVSS 9.3) — an unauthenticated RCE in PTC Windchill and FlexPLM — to steal manufacturing IP. Patch now or risk your engineering data ending…
Read More →CVE-2026-56155 (CVSS 7.8): ADFS DKM Zero-Day Hands Attackers Your Identity Signing Keys — CISA Deadline Is July 28
CVE-2026-56155 exploits misconfigured ADFS DKM container ACLs to steal token-signing keys, enabling Golden SAML forgery across every enterprise app. CISA deadline: July 28, 2026.
Read More →