Intigriti Bug Bytes #238 – July 2026
Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server…
Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server…
We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production…
The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine 30 Jul 2026 • , 6 min.…
The vulnerability carries a CVSS score of 9.8 out of 10 as it requires no authentication or user interaction, making internet-exposed TeamCity servers particularly attractive…
Choosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and…
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. The security issue is…
By John Grancarich, EVP, Head of Defense & Intelligence, Fortra The recent pause affecting the implementation of Cybersecurity Maturity Model Certification (CMMC) Phase II has understandably generated…
Bridewell’s BCON Collective has uncovered an active phishing infrastructure spanning more than 100 malicious domains after investigating what initially appeared to be a routine blocked…
It’s been a longtime feature of the annual Defcon hacker conference that attendees come away not only with knowledge of new software vulnerabilities and hacking…
Google has announced that its AI-assisted security workflows have helped Chrome fix 10,721 security vulnerabilities across Chrome Stable milestones 149 and 150. This number exceeds…
Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s…
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally…