Blog
CVE-2026-60004 (CVSS 9.8): Any Gitea User Can Hijack Your Server — A Public PoC Just Made Self-Hosted Git a Ticking Clock
CVE-2026-60004 is a CVSS 9.8 RCE in Gitea 1.17–1.27.0 that lets any user with repository write access execute OS commands on your server via Git hook injection. With open registration…
Read More →CVE-2026-60004 (CVSS 9.8): Any Gitea User Can Hijack Your Server — A Public PoC Just Made Self-Hosted Git a Ticking Clock
CVE-2026-60004 is a CVSS 9.8 RCE in Gitea 1.17–1.27.0 that lets any user with repository write access execute OS commands on your server via Git hook injection. With open registration…
Read More →ShinyHunters Claims EY Data Breach — Client Tax Records, SSNs, and a July 31 Extortion Deadline
ShinyHunters claims EY data breach exposing client SSNs and tax data via supply-chain attack. Extortion deadline is July 31, 2026 — here’s what security teams must do now.
Read More →Three Fortinet FortiSandbox CVEs Are Being Chained for Unauthenticated Root Access — CISA Deadline Passed, Exploitation Confirmed
CVE-2026-25089 (CVSS 9.8), CVE-2026-39808, and CVE-2026-39813 in Fortinet FortiSandbox are being chained by attackers for unauthenticated OS command execution. CISA KEV deadline passed — patch to 4.4.9 or 5.0.6 now.
Read More →CVE-2026-16812 (CVSS 10.0): Arista VeloCloud SD-WAN Orchestrator Zero-Day Is Being Actively Exploited — Patch by July 30
CVE-2026-16812 (CVSS 10.0) is an unauthenticated OS command injection in Arista VeloCloud Orchestrator being actively exploited. CISA KEV deadline is July 30. Patch on-prem VCO now.
Read More →TELESHIM: East Asia APT Abuses Telegram for C2 to Backdoor Government Systems — How Trusted Apps Become Attack Channels
East Asia APT deploys TELESHIM malware using Telegram Bot API for C2 to backdoor government systems. IOCs, technical breakdown, and zero-trust defences.
Read More →CVE-2026-54121 ‘Certighost’: Any Domain User Can Now Steal Your krbtgt — Working PoC Is Public, Patch AD CS Today
CVE-2026-54121 'Certighost' (CVSS 8.8): a public PoC lets any domain user impersonate a DC, run DCSync, and steal krbtgt. All Windows Server 2012-2025 affected. Patch now.
Read More →CVE-2026-16723 (CVSS 9.0): Fastjson 1.x Zero-Day Is Silently Hacking Spring Boot Apps — No Patch, Active Exploitation
CVE-2026-16723 is a CVSS 9.0 RCE in Fastjson 1.x with no patch available. Attackers are actively exploiting Spring Boot fat-JAR apps. Here's what to do right now.
Read More →CVE-2026-16232 (CVSS 9.3): Check Point SmartConsole Zero-Day Lets Attackers Rewrite Your Firewall Policy
CVE-2026-16232 (CVSS 9.3): Check Point SmartConsole zero-day grants full admin access with no credentials. Exploited in wild, CISA KEV listed — patch steps and IOCs inside.
Read More →No CVE, No Alert: GitLab Exploit Lets Any Authenticated User Hijack Your Server
A working GitLab RCE proof-of-concept released July 24 exploits Oj parser memory bugs. Any user with push access can run commands as git. No CVE assigned — patch to 18.11.5…
Read More →