Blog
FortiBleed 2026: Over 75,000 Fortinet Firewalls Silently Compromised — INC and Lynx Ransomware Are Cashing In
FortiBleed has compromised up to 86,644 Fortinet firewalls across 194 countries. INC Ransom and Lynx ransomware are now using stolen credentials. Patch FortiOS now.
Read More →CVE-2026-50242 (CVSS 10.0): JetBrains Hub Has a Database-Level Authentication Bypass — Patch Now or Hand Attackers Your Dev Pipeline
JetBrains Hub has a CVSS 10.0 unauthenticated admin bypass (CVE-2026-50242). Five companion CVEs hit YouTrack & IntelliJ IDEA. Here's what Indian IT teams must patch today.
Read More →CVE-2026-50242 (CVSS 10.0): JetBrains Hub Has a Database-Level Authentication Bypass — Patch Now or Hand Attackers Your Dev Pipeline
JetBrains Hub has a CVSS 10.0 unauthenticated admin bypass (CVE-2026-50242). Five companion CVEs hit YouTrack & IntelliJ IDEA. Here's what Indian IT teams must patch today.
Read More →ChocoPoC RAT: Fake GitHub PoC Repos Are Now Attacking Your Security Team
ChocoPoC RAT hides inside fake GitHub PoC repos to steal credentials from security researchers via malicious Python packages. Protect your team now.
Read More →CVE-2026-35273 (CVSS 9.8): ShinyHunters Exploited Oracle PeopleSoft as a Zero-Day for 13 Days — 100+ Organisations Breached
Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) was actively exploited as a zero-day by ShinyHunters for 13 days, compromising 100+ organisations globally. Patch PeopleTools 8.61/8.62 immediately.
Read More →CVE-2026-33825 BlueHammer (CVSS 7.8): Microsoft Defender Is Now a Ransomware Escalation Tool — Patch Before Your Next Incident
CISA confirms BlueHammer (CVE-2026-33825, CVSS 7.8) in Microsoft Defender is now used in active ransomware attacks. Check your Defender version — patch today.
Read More →CVE-2026-8451 (CVSS 8.8): Citrix NetScaler SAML Flaw Exploited Within 24 Hours — Is Your Identity Provider a Backdoor?
CVE-2026-8451 (CVSS 8.8) is a pre-auth NetScaler SAML memory overread exploited within 24 hours of disclosure. Patch to 14.1-72.61 or 13.1-63.18 now — here is what to do.
Read More →CVE-2026-45659 (CVSS 8.8): SharePoint RCE Now in CISA’s KEV — Storm-2603 Is Already Knocking
CISA added CVE-2026-45659 (CVSS 8.8) to its KEV catalog on July 1, 2026. This SharePoint Server RCE lets any Site Member execute code remotely—patch before July 4 or risk a…
Read More →CVE-2026-8037 (CVSS 9.8): Progress Kemp LoadMaster Pre-Auth RCE Is Under Active Attack — Patch Now or Hand Attackers Root
Attackers are actively probing CVE-2026-8037, a CVSS 9.8 pre-auth RCE in Progress Kemp LoadMaster. Upgrade to GA v7.2.63.2 or LTSF v7.2.54.18 immediately — no credentials needed to exploit.
Read More →CVE-2026-48558 (CVSS 10.0): Attackers Are Using SimpleHelp RMM to Deploy Djinn Stealer — Patch Before Your NOC Becomes a Backdoor
CVE-2026-48558 is a CVSS 10.0 OIDC auth bypass in SimpleHelp RMM. Attackers are already deploying Djinn Stealer across 14,000 servers. Here's what to patch now.
Read More →