A data theft plan is stealing information from anonymous users on Salesforce Experience Cloud and ServiceNow customer portals using special tools. The data theft campaign, called City-Forum by the software security company Reco, comes from one server that has attacked many groups around the world. These groups include phone companies, banks, …
Read More »“City-Forum” Campaign
Palo Alto Patches 11 New flaws Across PAN-OS, GlobalProtect, and Prisma Access
Palo Alto Networks shared its security bulletin revealing 11 new issues that impact PAN-OS, the GlobalProtect App, Prisma Access Agent, and Prisma Browser. There is also a monthly update for Chromium. The patch batch covers flaws with information leaks, getting extra system rights, buffer overflow, skipping certificate checks, and bypassing …
Read More »Microsoft Patch 394 Flaws, Including 3 Zero-Days
Microsoft announced fixes for 394 CVEs on Tuesday, including a serious flaw that has been used by hackers as a zero-day. The security flaw called CVE-2026-68820 is a use-after-free bug in the Ancillary Function Driver for WinSock (afd.sys). This driver works in kernel mode and is essential for the Windows Sockets …
Read More »Hacker Actively Exploit SonicWall and SharePoint Flaws
The CISA in the U.S. has added two important SonicWall SMA1000 flaws—CVE-2026-15409 and CVE-2026-15410-to its list of Known Exploited Vulnerabilities after finding they are used in ransomware attacks. SonicWall showed the flaws on July 14, 2026, after checking for active use. The issues impact SMA 6210, SMA 7210, and SMA …
Read More »Google Play Apps Utilize Stealth Loaders to Spread Anatsa Banking Malware
Android users are reminded that a known app store listing can hold a money threat. Researchers found harmful loaders on Google Play that can set up Anatsa, an Android banking Trojan that can put account access in danger. The campaign starts without a clear harmful download. It uses what looks …
Read More »Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns
The gentlemen ransomware group targets various industries of Bangladesh. In an advisory Bangladesh e-Government Computer Incident Response Team (BGD e-GOV CIRT) warned that the ransomware operates under a Ransomware-as-a-Service (RaaS) model and is capable of rapidly spreading across corporate networks, encrypting Windows and Linux systems, network storage devices and VMware …
Read More »Google Chrome 151 Update Fixes 41 Flaws, 6 Critical
Google has launched Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update brings 41 security fixes for different parts of the browser, such as rendering, graphics, JavaScript, user interface (UI), media, and authentication. Google Chrome 151 Update The update fixes six serious memory issues. Five …
Read More »Urgent patch! Cisco and IMB patch multiple flaws
Cisco has put out an important update for Cisco IOS XE Software. This update fixes serious security holes that could let remote attacks target enterprise network devices. The flaws can impact Cisco IOS XE Software in both autonomous mode and controller mode, no matter how the device is set up. …
Read More »
CVE-2026-18574
Check Point Authentication Bypass Hits Management Server
Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue is tracked as CVE-2026-18574 and has a CVSS score of 9.3. Check Point discovered the problem themselves and says there are no current attacks. Why it matters An attacker without …
Read More »TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise
TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as CVE-2026-12935, might let attackers who haven’t logged in cause a denial-of-service issue or run their code on affected devices in some situations. According to TP-Link, the vulnerability is caused by …
Read More »
InfoSecBulletin Cybersecurity for mankind