Blog
FBI FLASH: TeamPCP’s Supply Chain Worm Poisons Trusted Dev Tools — Your CI/CD Pipeline May Already Be Breached
FBI FLASH exposes TeamPCP, who poisoned Trivy, KICS & LiteLLM to steal AWS, GCP and Azure credentials from CI/CD pipelines. Rotate secrets now.
Read More →Adobe ColdFusion Under Active Attack: CVE-2026-48282 & 6 More CVSS 10.0 Flaws — Patch Now Before Your Server Is Next
Adobe patched 7 CVSS 10.0 ColdFusion flaws on 1 July 2026. CVE-2026-48282 is exploited in the wild — an Indian IP was the first attacker. Patch to Update 21 or…
Read More →CVE-2026-46242 “Bad Epoll” (CVSS 7.8): Any Linux User Can Become Root — Patch Now Before Attackers Do It For You
CVE-2026-46242 "Bad Epoll" is a use-after-free flaw letting any local Linux user gain root with 99% exploit reliability. Patch to 6.6.144+, 6.12.95+, or 6.18.33+ now.
Read More →FortiBleed 2026: Over 75,000 Fortinet Firewalls Silently Compromised — INC and Lynx Ransomware Are Cashing In
FortiBleed has compromised up to 86,644 Fortinet firewalls across 194 countries. INC Ransom and Lynx ransomware are now using stolen credentials. Patch FortiOS now.
Read More →CVE-2026-50242 (CVSS 10.0): JetBrains Hub Has a Database-Level Authentication Bypass — Patch Now or Hand Attackers Your Dev Pipeline
JetBrains Hub has a CVSS 10.0 unauthenticated admin bypass (CVE-2026-50242). Five companion CVEs hit YouTrack & IntelliJ IDEA. Here's what Indian IT teams must patch today.
Read More →CVE-2026-50242 (CVSS 10.0): JetBrains Hub Has a Database-Level Authentication Bypass — Patch Now or Hand Attackers Your Dev Pipeline
JetBrains Hub has a CVSS 10.0 unauthenticated admin bypass (CVE-2026-50242). Five companion CVEs hit YouTrack & IntelliJ IDEA. Here's what Indian IT teams must patch today.
Read More →ChocoPoC RAT: Fake GitHub PoC Repos Are Now Attacking Your Security Team
ChocoPoC RAT hides inside fake GitHub PoC repos to steal credentials from security researchers via malicious Python packages. Protect your team now.
Read More →CVE-2026-35273 (CVSS 9.8): ShinyHunters Exploited Oracle PeopleSoft as a Zero-Day for 13 Days — 100+ Organisations Breached
Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) was actively exploited as a zero-day by ShinyHunters for 13 days, compromising 100+ organisations globally. Patch PeopleTools 8.61/8.62 immediately.
Read More →CVE-2026-33825 BlueHammer (CVSS 7.8): Microsoft Defender Is Now a Ransomware Escalation Tool — Patch Before Your Next Incident
CISA confirms BlueHammer (CVE-2026-33825, CVSS 7.8) in Microsoft Defender is now used in active ransomware attacks. Check your Defender version — patch today.
Read More →CVE-2026-8451 (CVSS 8.8): Citrix NetScaler SAML Flaw Exploited Within 24 Hours — Is Your Identity Provider a Backdoor?
CVE-2026-8451 (CVSS 8.8) is a pre-auth NetScaler SAML memory overread exploited within 24 hours of disclosure. Patch to 14.1-72.61 or 13.1-63.18 now — here is what to do.
Read More →