Blog
CVE-2026-12569 (CVSS 9.3): Cl0p Is Raiding Manufacturing PLM Systems — Patch PTC Windchill and FlexPLM Before Your IP Is Gone
Cl0p ransomware affiliates are exploiting CVE-2026-12569 (CVSS 9.3) — an unauthenticated RCE in PTC Windchill and FlexPLM — to steal manufacturing IP. Patch now or risk your engineering data ending…
Read More →CVE-2026-56155 (CVSS 7.8): ADFS DKM Zero-Day Hands Attackers Your Identity Signing Keys — CISA Deadline Is July 28
CVE-2026-56155 exploits misconfigured ADFS DKM container ACLs to steal token-signing keys, enabling Golden SAML forgery across every enterprise app. CISA deadline: July 28, 2026.
Read More →TeamPCP Poisoned Trivy, KICS, and LiteLLM to Harvest 500,000 Credentials — Now Vect Ransomware Is Cashing In
TeamPCP compromised Trivy, KICS, and LiteLLM to steal 500,000 CI/CD credentials across 500,000 machines. Now Vect ransomware is deploying against victims — and paying the ransom may not recover your…
Read More →JadePuffer: The World’s First Fully Autonomous AI Ransomware Has Arrived — And It Needs No Human Operator
JADEPUFFER is the first confirmed ransomware campaign executed entirely by a large language model agent — exploiting CVE-2025-3248 (CVSS 9.8) in Langflow to autonomously encrypt 1,342 production configs without any…
Read More →Iran’s CyberAv3ngers Are Inside Your Water and Energy Systems — CISA’s July 22 Update Expands Alert to Siemens and Schneider PLCs
CISA updated AA26-097A on July 22, 2026: Iran-backed CyberAv3ngers now target Siemens & Schneider PLCs. CVE-2021-22681 has no patch — act now.
Read More →China-Linked UAT-7810 Turns Ruckus and ASUS Routers Into Covert Spy Relays — The LapDogs ORB Network Is Growing
China-nexus APT UAT-7810 hijacks unpatched Ruckus and ASUS routers with LONGLEASH malware to build a covert ORB relay network — CVE-2023-25717 (CVSS 9.8) and CVE-2025-2492 (CVSS 9.2) are the entry…
Read More →CVE-2026-50522 (CVSS 9.8): SharePoint Machine Key Theft Turns Patched Servers Into Persistent Backdoors
CVE-2026-50522 (CVSS 9.8) pre-auth SharePoint RCE is actively exploited to steal IIS machine keys — granting persistent backdoor access that survives patching. Here is the technical breakdown and what to…
Read More →CVE-2026-6875 (CVSS 9.5): No Password Required — Attackers Are Actively Exploiting ServiceNow’s Pre-Auth Sandbox Escape
CVE-2026-6875 (CVSS 9.5) lets unauthenticated attackers escape ServiceNow’s sandbox and execute code remotely. Active exploitation confirmed since July 18, 2026. Self-hosted customers must patch immediately.
Read More →Hugging Face Hacked by Autonomous AI Agent: 17,000 Actions, Stolen Credentials — AI-on-AI Attacks Are Here
Autonomous AI agent hacked Hugging Face, executing 17,000 actions to steal credentials and move laterally across clusters. Here's what happened and how to defend your AI infrastructure.
Read More →CVE-2026-42533: NGINX’s Hidden 15-Year Flaw (CVSS 9.2) Threatens Every Web Server — Patch Before the PoC Drops
CVE-2026-42533 is a critical NGINX heap buffer overflow (CVSS 9.2) hiding since 2011. Patch to nginx 1.30.4 or 1.31.3 now — a PoC exploit drops by 5 August.
Read More →