Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Ravie LakshmananJul 21, 2026Vulnerability / Cloud Security Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real…
Ravie LakshmananJul 21, 2026Vulnerability / Cloud Security Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real…
Ravie LakshmananJul 21, 2026Vulnerability / Network Security Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point…
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable…
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons…
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments,…
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol…
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files…
Swati KhandelwalJul 20, 2026Vulnerability / Endpoint Security Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw,…
Ravie LakshmananJul 19, 2026Vulnerability / Network Security A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access…
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with…
Ravie LakshmananJul 19, 2026Malware / Cyber Warfare Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting…
Ravie LakshmananJul 17, 2026Cyber Espionage / Threat Intelligence Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in…