NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run code on these systems if they take advantage of it. This security flaw, known as CVE-2026-65094, affects the VIRTIO-Net part and has a CVSS v3.1 score of 9.0, showing it is …
Read More »Shinyhunters claimed and set deadline to publish E&Y data
ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their dark web site. It says they will release all stolen data by July 31, 2026, unless EY talks to them before the mentioned date. EY shared details about the incident …
Read More »Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws
ASUS has put out important security updates for a serious router flaw. This issue could let remote hackers run any commands on the affected devices. The flaw, known as CVE-2026-13385, affects many ASUS router firmware versions, such as the commonly used 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. The ASUS Product Security Advisory …
Read More »Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers
Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were probably found by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. Vulnerabilities have been fixed in products like Database …
Read More »Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws
Zimbra has launched updates to fix serious security flaws, including a command injection bug in the SNMP monitoring part. As many as nine security flaws have been fixed in Zimbra 10.1.20. The biggest issue is a command injection problem in the SNMP monitoring part when SNMP alerts are turned on. …
Read More »Qilin ransomware gang exploiting critical Palo Alto VPN Flaw
The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims’ networks, says the cybersecurity firm Arctic Wolf. Palo Alto Networks fixed the flaw (CVE-2026-0257) on May 13 and warned that hackers started using it to break into company networks. Rapid7 reported seeing this attack on many …
Read More »
CVE-2026-60137, CVE-2026-63030
Patch immediately! 2 high severity WordPress flaws found
The WordPress security team received reports about these flaws: CVE-2026-60137 : A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-63030 : A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber …
Read More »Windows LegacyHive 0, AWS, Fortinet, TP-LINK multiple flaws got hackers attention
A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges, change admin accounts, and run code with admin rights. The public proof‑of‑concept (PoC) from the MSNightmare GitHub account describes the bug as a “Windows user profile service arbitrary hive load …
Read More »
CVE-2026-53412
Zoom Warns of critical account takeover Flaw via Network Access
Zoom has issued updates for a flaw in the Windows desktop client, known as CVE-2026-53412. This issue may allow an unauthenticated user to conduct an account takeover via network access. This flaw arises from improper input validation and may enable unauthenticated attackers to execute account takeover attacks via network access. …
Read More »Microsoft Patch Tuesday July-2026 fixes 570 flaws, 3 zero-days
Microsoft’s Patch Tuesday in July 2026 fixes around 570 security flaws in its products. This comes after June’s big update, which had a record 206 issues and three that were already known to the public. This big update comes after Microsoft’s recent change to use artificial intelligence for finding security …
Read More »
InfoSecBulletin Cybersecurity for mankind