Aggregator
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS is a Microsoft Windows Server role that lets an organization run its own Public Key Infrastructure (PKI). It acts as a Certificate Authority (CA), issuing and managing digital certificates used for authentication, encryption, and signing across … More →
The post PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) appeared first on Help Net Security.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
- CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Hackers used autonomous AI agent to spy on Thailand's finance ministry
Е-сим против вас: мошенники научились красть номера без пароля и смс
Europol Launches Project COMPASS to Disrupt ‘The Com’ Cybercrime Network Targeting Minors
Europol has launched Project COMPASS, a coordinated transnational initiative aimed at disrupting “The Com,” a highly dangerous cybercrime and nihilistic extremist network that systematically targets minors and vulnerable young people across digital platforms. The Com operates as a sprawling transnational virtual network (TVN), utilizing social media, messaging apps, music platforms, and online games to recruit, […]
The post Europol Launches Project COMPASS to Disrupt ‘The Com’ Cybercrime Network Targeting Minors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
【漏洞通告】Fastjson 2.x远程代码执行漏洞
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain
EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency
vBulletin Pre-Auth RCE Flaw Allows Remote PHP Code Execution
A critical pre-authentication remote code execution vulnerability in vBulletin, tracked as CVE-2026-61511, could allow unauthenticated attackers to execute arbitrary PHP code on vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier, as well as 6.1.6 and earlier, according to a July 27, 2026, disclosure from SSD Secure Disclosure. If exploited successfully, this vulnerability […]
The post vBulletin Pre-Auth RCE Flaw Allows Remote PHP Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Insight Partners and Glilot Capital Co-Lead $20M Investment in Way Security
ChatGPT joins the most impersonated brands in phishing attacks
Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, according to Check Point’s Q2 2026 Brand Phishing Report. Fake ChatGPT Plus billing email (Source: Check Point) Technology remains the top target, but… Brand phishing exploits trusted brands people recognise and … More →
The post ChatGPT joins the most impersonated brands in phishing attacks appeared first on Help Net Security.
顶会入选 | COVERT —— 面向视觉语言模型的隐私保护推理框架入选 ECCV 2026
Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware
A newly uncovered cluster of more than 70 impersonation domains targeting popular Windows applications is raising fresh concerns about a scalable malware distribution campaign that leverages trust in legitimate software ecosystems. The discovery, triggered by a developer investigating unusual search results for their own application, reveals a coordinated infrastructure designed to mimic well-known tools while […]
The post Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
США вернули технологию Манхэттенского проекта — теперь она спасает квантовые компьютеры от шума
Google Indexed Claude AI Shared Chats Before Results Were Removed
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
AI与云安全事件案例分析周报2026.07.20 - 2026.07.24
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply chain attacks where attackers publish trojanized package versions to public registries, relying on automated update […]
The post GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.