Skip to content
Wednesday, Jul 29, 2026

Cyber News Reports

Concise articles to keep you updated, without the fluff

Subscribe

Author: Zaran

Public Exploit Released for Patched vBulletin RCE Vulnerability (CVE-2026-61511)
vulnerability disclosureWeb Security

Public Exploit Released for Patched vBulletin RCE Vulnerability (CVE-2026-61511)

A public exploit has been released for a pre-authentication remote code execution (RCE) vulnerability in vBulletin. Unauthenticated attackers can now execute arbitrary PHP code on vulnerable forums,.

by ZaranJuly 29, 2026July 29, 2026
Unpatched Fastjson Vulnerability Actively Exploited with No Fix Available
Java SecurityVulnerability Exploitation

Unpatched Fastjson Vulnerability Actively Exploited with No Fix Available

Attackers are actively exploiting a critical remote code execution (RCE) vulnerability in Alibaba’s Fastjson 1.x library, CVE-2026-16723. The unpatched flaw affects versions 1.2.68 through 1.2.83 and.

by ZaranJuly 27, 2026July 29, 2026
Malware Campaign Hijacks Chrome via Enterprise Policy Keys and DLL Side-Loading
Browser SecurityMalware Analysis

Malware Campaign Hijacks Chrome via Enterprise Policy Keys and DLL Side-Loading

A sophisticated malware campaign has been discovered abusing legitimate Google Chrome enterprise policy keys to hijack user browsers, bypassing security measures with DLL side-loading techniques.

by ZaranJune 29, 2026June 29, 2026
Klue Hack Impacts Salesforce, Gong Integrations via Icarus Threat Actor
Data BreachesSupply Chain Attacks

Klue Hack Impacts Salesforce, Gong Integrations via Icarus Threat Actor

A supply chain attack targeting Klue has exposed sensitive customer data and disrupted integrations with Salesforce and other platforms. The ‘Icarus’ threat actor exploited a compromised legacy.

by ZaranJune 29, 2026June 29, 2026
Cisco Unified CM Flaw (CVE-2026-20230) Actively Exploited for Webshell Deployment and Root Access
Exploitation in the Wildvulnerability disclosure

Cisco Unified CM Flaw (CVE-2026-20230) Actively Exploited for Webshell Deployment and Root Access

A critical server-side request forgery (SSRF) vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager is being actively exploited to deploy webshells and achieve root access. Patches.

by ZaranJune 28, 2026June 28, 2026
One Medical Faces Data Breach Claim: ShinyHunters Alleges Theft of 8.8TB of Healthcare Data
Data BreachesHealthcare Security

One Medical Faces Data Breach Claim: ShinyHunters Alleges Theft of 8.8TB of Healthcare Data

ShinyHunters claims to have stolen a massive 8.8TB of data from One Medical, Amazon’s healthcare provider, threatening release unless negotiations begin by June 22nd. The breach reportedly involves.

by ZaranJune 22, 2026June 22, 2026
WhatsApp Malware Campaign Delivers VBS Files, Enabling Remote Access on Windows Systems
malwareWindows Security

WhatsApp Malware Campaign Delivers VBS Files, Enabling Remote Access on Windows Systems

A sophisticated malware campaign is using WhatsApp to distribute malicious Visual Basic Script (VBS) files targeting Windows users across multiple countries. The attack, which began in late February.

by ZaranJune 22, 2026June 22, 2026
Unpatchable BootROM Vulnerability Affects Apple A12 & A13 Devices
Mobile SecurityVulnerabilities

Unpatchable BootROM Vulnerability Affects Apple A12 & A13 Devices

A newly discovered, unpatchable vulnerability dubbed ‘usbliter8’ impacts Apple devices with A12 and A13 chips. The exploit leverages a hardware bug in the USB controller and firmware misconfiguration.

by ZaranJune 19, 2026June 19, 2026
Crypto Clipper Malware Uses Tor, USB Propagation, and Worm-Like Behavior to Steal Cryptocurrency
cybercrimemalware

Crypto Clipper Malware Uses Tor, USB Propagation, and Worm-Like Behavior to Steal Cryptocurrency

A sophisticated cryptocurrency clipper malware campaign has been active since February 2026, using Tor for command and control, spreading via malicious USB drives, and employing worm-like propagation.

by ZaranJune 19, 2026June 19, 2026
Palo Alto GlobalProtect VPN Vulnerability Actively Exploited, CISA Issues Warning
Cybersecurity Newsvulnerability disclosure

Palo Alto GlobalProtect VPN Vulnerability Actively Exploited, CISA Issues Warning

Unauthenticated attackers are actively exploiting a high-severity authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks’ GlobalProtect VPN. CISA has added the flaw to its KEV.

by ZaranJune 16, 2026June 16, 2026

Posts navigation

Older posts

Categories

  • Browser Security
  • cybercrime
  • Cybersecurity Incident
  • Cybersecurity News
  • Cybersecurity Policy
  • Data Breach
  • Data Breaches
  • Exploitation in the Wild
  • Government Security
  • Healthcare Security
  • incident response
  • Java Security
  • malware
  • Malware Analysis
  • Mobile Security
  • Supply Chain Attacks
  • Vulnerabilities
  • vulnerability disclosure
  • Vulnerability Exploitation
  • Vulnerability Response
  • Web Security
  • Windows Security

Copyright © 2026 Cyber News Reports | Premier News by Ascendoor | Powered by WordPress.