Blog
RovoBlast: Atlassian’s AI Agent Can Be Weaponised to Drain Every Jira Ticket, Confluence Page and SharePoint File You Own
Two prompt-injection flaws in Atlassian Rovo let attackers exfiltrate all your Jira, Confluence and SharePoint data. One attack path remains unpatched after 74 days.
Read More →CVE-2026-64638 (CVSS 8.9): WordPress XSS2Shell Turns a Failed Login Into Full PHP Code Execution — Patch to 7.0.3 Now
CVE-2026-64638 (CVSS 8.9) turns any WordPress login attempt into full PHP remote code execution. Learn how XSS2Shell works and why all sites must patch to WordPress 7.0.3 immediately.
Read More →TONTOU Attack (AMD-SB-7061): MIT Breaks Every Spectre v2 Mitigation on Linux — Unprivileged Code Steals Root Password Hashes in 18 Minutes
MIT CSAIL researchers demonstrated TONTOU at Black Hat USA 2026 — a new Interrupt Injection attack that bypasses all AMD Safe RET (Spectre v2) mitigations on Linux. Patch Linux kernels…
Read More →CVE-2026-63077 (CVSS 9.8): JetBrains TeamCity’s Unauthenticated RCE Hits Active Exploitation — CISA Patch Deadline August 8
CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in JetBrains TeamCity, is under active exploitation. CISA patch deadline is August 8, 2026. Patch now.
Read More →CVE-2025-68686: The “Double Slash” That Revives Your Patched FortiOS SSL-VPN Backdoor — CISA Deadline August 10
CVE-2025-68686 bypasses Fortinet’s own patch for FortiOS SSL-VPN symlink persistence attacks — a doubled slash in an HTTP request defeats the filter. CISA deadline: August 10, 2026.
Read More →CVE-2026-34486 (CVSS 7.5): Apache Tomcat’s Broken Cluster Patch Enables Unauthenticated RCE — CISA Adds to KEV as SNOWLIGHT Campaign Hits 100+ Countries
CISA adds CVE-2026-34486 to KEV as China-linked attackers exploit a broken Apache Tomcat cluster patch to deliver SNOWLIGHT malware across 100+ countries.
Read More →CVE-2026-9198 (CVSS 9.8): Hackers Are Using Two API Calls to Own Your AI Infrastructure — Langflow Hits CISA’s Must-Patch List
CISA flags CVE-2026-9198 (CVSS 9.8): Langflow AI platform exploited via two unauthenticated API calls. Patch to v1.10.1 before August 7 deadline.
Read More →CaptiveCrunch: Russia’s Midnight Blizzard Is Hijacking Hotel Wi-Fi to Steal Your Microsoft 365 Credentials
Russia's Midnight Blizzard (APT29) is hijacking hotel Wi-Fi via the CaptiveCrunch campaign, deploying CornFlake RAT and ChocoShell to steal Microsoft 365 tokens from corporate travellers worldwide.
Read More →CVE-2026-45321: Mini Shai-Hulud npm Worm Poisons 420 Packages and 2 Billion Monthly Installs — Claude Code and VS Code Weaponised as Persistence Hooks
The Mini Shai-Hulud npm worm compromised 420+ packages and 2B monthly installs on Aug 4. Learn how it spread, what credentials it stole, and how to remove it safely.
Read More →CVE-2026-15409 (CVSS 10.0): INC Ransomware Chains SonicWall SMA1000 Zero-Days to Hijack VPN Infrastructure — 885 Victims and Counting
INC Ransomware weaponises CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in SonicWall SMA1000 appliances. Patch to 12.4.3-03453 now — 885 victims listed globally.
Read More →