Blog
GoldenEyeDog Breached DigiCert and Armed 27 Stolen EV Code-Signing Certificates — Zero Trust Is Now Your Only Defence
Chinese APT CylindricalCanine breached DigiCert via a support chat screensaver, stealing 27 EV code-signing certificates now used to sign Zhong Stealer malware targeting APAC finance firms.
Read More →wp2shell (CVE-2026-63030, CVSS 9.8): One HTTP Request Can Own Your WordPress Site — Patch Now
Critical pre-auth RCE in WordPress Core (CVE-2026-63030, CVSS 9.8) lets attackers own any WordPress 6.9–7.0 site with a single anonymous request. Patch to 6.9.5 or 7.0.2 immediately.
Read More →CISA Mandate: Patch Fortinet FortiSandbox Now — Three CVSS 9.1 Flaws Under Active Attack (Federal Deadline July 19)
Three CVSS 9.1 Fortinet FortiSandbox vulnerabilities (CVE-2026-25089, CVE-2026-39808, CVE-2026-39813) are actively exploited — CISA KEV added July 16 with a federal patch deadline of July 19. Patch to 4.4.9 or…
Read More →SonicWall SMA1000 Zero-Day Chain (CVE-2026-15409 CVSS 10.0): Attackers Are Stealing VPN Credentials and MFA Seeds — Patch Today
Two actively exploited SonicWall SMA1000 zero-days chain to steal VPN credentials and MFA seeds. CISA deadline is today, July 17. Patch now or re-image if compromised.
Read More →LegacyHive: Unpatched Windows Zero-Day Drops Hours After Patch Tuesday — Every Supported Version at Risk
LegacyHive is an unpatched Windows User Profile Service privilege escalation zero-day released hours after July 2026 Patch Tuesday. Every supported Windows version is affected — here is the technical breakdown…
Read More →Microsoft Patch Tuesday July 2026: 570 Flaws, Two Actively Exploited Zero-Days in AD FS and SharePoint
Microsoft’s July 2026 Patch Tuesday — the largest in company history at ~570 CVEs — includes two actively exploited zero-days: CVE-2026-56155 (AD FS, CVSS 7.8) and CVE-2026-56164 (SharePoint, CVSS 5.3).…
Read More →No Password Needed: CVE-2026-46817 (CVSS 9.8) Gives Attackers Full Access to Oracle EBS Payments Over Plain HTTP — 950+ Instances Exposed
CVE-2026-46817 (CVSS 9.8) in Oracle EBS Payments is under active attack — 950+ instances exposed, no auth needed. Here's what to patch and check now.
Read More →One HTTP Header = Admin Access: CVE-2026-20896 Actively Exploited in the Wild — Patch Your Gitea Now
CVE-2026-20896 (CVSS 9.8) allows attackers to impersonate any Gitea admin with a single HTTP header. Active exploitation confirmed. Patch to 1.26.4 now.
Read More →CVE-2026-53359 “Januscape”: 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to the Host — Patch Now
CVE-2026-53359 'Januscape' is a 16-year-old Linux KVM shadow MMU flaw (CVSS 8.8/9.3) enabling guest VMs to escape to the host on Intel and AMD. Here's how to patch and protect…
Read More →JadePuffer: The World’s First AI-Agent Ransomware — No Human Operator Required
Sysdig has captured JadePuffer — the world's first fully AI-agent-driven ransomware. It exploited CVE-2025-3248 in Langflow, adapted in real time, and encrypted 1,342 production records autonomously.
Read More →