Category: Vulnerabilities
ICS Patch Tuesday: Siemens, Schneider, Rockwell Fix Critical Flaws in July 2026
Siemens leads July's ICS Patch Tuesday with a maximum-severity authentication bypass in Opencenter X, while Rockwell and Schneider Electric address critical and…
Progress Confirms Zero-Day Behind ShareFile Outage, Restores Access
Progress Software says a path traversal zero-day in ShareFile Storage Zones Controller prompted an emergency shutdown of customer servers, with patched access…
SAP Patches Critical CVSS 9.9 NetWeaver Flaw Among 16 July Fixes
SAP's July 2026 patch batch closes three critical vulnerabilities in NetWeaver, Approuter, and Commerce Cloud, headlined by a near-maximum-severity memory corruption bug…
SonicWall SMA1000 Zero-Days Under Active Attack, CISA Sets Federal Patch Deadline
SonicWall confirms two SMA1000 vulnerabilities, including a maximum-severity SSRF flaw, are being exploited in the wild. CISA has added both to its…
Microsoft Ships Windows 10 KB5099539, Bundling Record July Patch Tuesday Fixes
The extended security update patches July 2026's record-breaking 570 vulnerabilities for ESU-enrolled and LTSC devices, while adding networking hardening and RDP certificate…
Microsoft’s July Patch Tuesday Sets Record With 622 Fixes, Two Zero-Days Under Attack
Microsoft's largest security update on record addresses 622 vulnerabilities this month, including actively exploited flaws in Active Directory Federation Services and SharePoint…
Jscrambler NPM Package Hijacked to Push Rust Info-Stealer Malware
A threat actor used stolen NPM publishing credentials to push malicious versions of Jscrambler's popular code protection package, embedding a preinstall hook…
Nihon Kotsu, Japan’s Largest Taxi Operator, Shuts Down Systems After Malware Attack
A weekend malware intrusion knocked out dispatch, booking, and reservation systems at Nihon Kotsu, forcing Japan's biggest taxi and chauffeur operator to…
US Sanctions VPN Provider First VPN for Enabling Ransomware Attacks
Treasury sanctioned First VPN Service and its Ukrainian administrator for supplying anonymizing infrastructure to ransomware gangs, alongside a Belarusian seller of malware-cloaking…
Critical Joomla Extension Flaws Under Active Exploitation, CISA Adds to KEV
Unauthenticated file upload vulnerabilities in the Balbooa Forms and iCagenda Joomla extensions, both scoring a maximum CVSS of 10, are being exploited…
US and Allies Warn Russian FSB Hackers Are Hunting Weak Router Configs
A joint advisory from CISA, the NSA, FBI, and agencies in eight allied nations warns that Russia's FSB Center 16 group is…
Attackers Exploit Critical Auth Bypass in Gitea’s Official Docker Image
A misconfigured default in Gitea's Docker image lets unauthenticated attackers impersonate any user, including admins, and exploitation began before public disclosure.