CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Adobe ColdFusion vulnerability, tracked as CVE-2026-48282, to its Known Exploited Vulnerabilities (KEV) catalog, warning that …

70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent study has revealed that more than 70% of publicly accessible WordPress websites are running outdated versions of PHP, significantly increasing their exposure to cyberattacks. The findings highlight a …

Hackers Exploit Roundcube N-Day Flaws to Steal Credentials and Deploy VShell

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 A newly identified hacking campaign is targeting university mail servers by exploiting known but unpatched flaws in Roundcube webmail software. The attackers are using these gaps to …

China-Nexus Hackers Exploit Ruckus Routers to Build Operational Relay Box Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 UAT-7810, a China-nexus hacking group, is expanding a global network of hijacked internet devices by exploiting security flaws in Ruckus wireless routers and rolling out new custom …

15-year-old GhostLock Kernel Flaw Enables Privilege Escalation in Major Linux Distributions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 A critical Linux kernel vulnerability, tracked as CVE-2026-43499 and dubbed “GhostLock,” has been disclosed by security researchers at VEGA, exposing a privilege escalation flaw that has silently …

Accenture Data Breach – Hackers Allegedly Claim to Have Stolen 35 GB of Source Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor operating under the alias “888” has posted a listing on a cybercrime forum claiming to sell data allegedly stolen from the IT services and consulting giant Accenture, …

Critical Vulnerability in GCP Dialogflow Allows Attackers to Inject Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A critical vulnerability in Google Cloud Platform’s Dialogflow CX that lets attackers inject persistent malicious code into an organization’s AI-powered chatbot pipeline. The flaw, dubbed “Rogue Agent,” …

The Gentlemen Ransomware With Custom EDR/AV Killers Scaling Faster to Attack Industries Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026. Emerging in mid-2025 from a payment dispute within the Qilin RaaS program, the group has evolved …