Blog
China-Linked UAT-7810 Turns Ruckus and ASUS Routers Into Covert Spy Relays — The LapDogs ORB Network Is Growing
China-nexus APT UAT-7810 hijacks unpatched Ruckus and ASUS routers with LONGLEASH malware to build a covert ORB relay network — CVE-2023-25717 (CVSS 9.8) and CVE-2025-2492 (CVSS 9.2) are the entry…
Read More →CVE-2026-50522 (CVSS 9.8): SharePoint Machine Key Theft Turns Patched Servers Into Persistent Backdoors
CVE-2026-50522 (CVSS 9.8) pre-auth SharePoint RCE is actively exploited to steal IIS machine keys — granting persistent backdoor access that survives patching. Here is the technical breakdown and what to…
Read More →CVE-2026-6875 (CVSS 9.5): No Password Required — Attackers Are Actively Exploiting ServiceNow’s Pre-Auth Sandbox Escape
CVE-2026-6875 (CVSS 9.5) lets unauthenticated attackers escape ServiceNow’s sandbox and execute code remotely. Active exploitation confirmed since July 18, 2026. Self-hosted customers must patch immediately.
Read More →Hugging Face Hacked by Autonomous AI Agent: 17,000 Actions, Stolen Credentials — AI-on-AI Attacks Are Here
Autonomous AI agent hacked Hugging Face, executing 17,000 actions to steal credentials and move laterally across clusters. Here's what happened and how to defend your AI infrastructure.
Read More →CVE-2026-42533: NGINX’s Hidden 15-Year Flaw (CVSS 9.2) Threatens Every Web Server — Patch Before the PoC Drops
CVE-2026-42533 is a critical NGINX heap buffer overflow (CVSS 9.2) hiding since 2011. Patch to nginx 1.30.4 or 1.31.3 now — a PoC exploit drops by 5 August.
Read More →GodDamn Ransomware’s Signed PoisonX Driver Is Silently Killing Your EDR — Inside Hyadina’s BYOVD Playbook
Hyadina's GodDamn ransomware uses a Microsoft-signed malicious kernel driver (PoisonX/g11.sys) to disable EDR and AV before encrypting 10+ hosts. Here's the full BYOVD attack chain and how to stop it.
Read More →FEDERAL DEADLINE TODAY: CVE-2026-58644 SharePoint Zero-Day (CVSS 9.8) Exploited in the Wild — CISA Mandates Immediate Patching
CVE-2026-58644 (CVSS 9.8) is a zero-day unauthenticated RCE in SharePoint Server now on CISA's KEV list. Federal deadline is today — here's what to patch and how to check if…
Read More →GoldenEyeDog Breached DigiCert and Armed 27 Stolen EV Code-Signing Certificates — Zero Trust Is Now Your Only Defence
Chinese APT CylindricalCanine breached DigiCert via a support chat screensaver, stealing 27 EV code-signing certificates now used to sign Zhong Stealer malware targeting APAC finance firms.
Read More →wp2shell (CVE-2026-63030, CVSS 9.8): One HTTP Request Can Own Your WordPress Site — Patch Now
Critical pre-auth RCE in WordPress Core (CVE-2026-63030, CVSS 9.8) lets attackers own any WordPress 6.9–7.0 site with a single anonymous request. Patch to 6.9.5 or 7.0.2 immediately.
Read More →CISA Mandate: Patch Fortinet FortiSandbox Now — Three CVSS 9.1 Flaws Under Active Attack (Federal Deadline July 19)
Three CVSS 9.1 Fortinet FortiSandbox vulnerabilities (CVE-2026-25089, CVE-2026-39808, CVE-2026-39813) are actively exploited — CISA KEV added July 16 with a federal patch deadline of July 19. Patch to 4.4.9 or…
Read More →