Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
A single wrong variable on one line in XQUIC, Alibaba’s QUIC and HTTP/3 library, lets any remote client crash the server with a short burst…
A single wrong variable on one line in XQUIC, Alibaba’s QUIC and HTTP/3 library, lets any remote client crash the server with a short burst…
Ravie LakshmananJul 10, 2026Malware / Enterprise Security The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan…
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between…
The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries…
Researchers at Ledger’s Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the…
Ravie LakshmananJul 11, 2026Vulnerability / Email Security Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client…
Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras,…
Ravie LakshmananJul 10, 2026Software Supply Chain / Malware Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a…
Swati KhandelwalJul 10, 2026Enterprise Security / Security Incident Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers,…
Ravie LakshmananJul 10, 2026AI Security / Vulnerability Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if…
Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated…
Ravie LakshmananJul 09, 2026Supply Chain Security / DevSecOps GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along…