July 29, 2026 Russia’s Federal Security Service (FSB) has formally charged Telegram founder and CEO Pavel Durov with aiding terrorism and issued a warrant for his arrest, escalating a long-running …
Houston City College Data Breach Exposes 832k Unique Student Email Addresses
July 29, 2026 Houston City College has experienced a serious data breach that exposed sensitive personal information of approximately 832,000 unique students and alums. This incident is linked to a …
AsyncAPI Malware Contains Modules to Steal GitHub, npm, Cloud and AI API Credentials
July 29, 2026 A dangerous supply chain attack struck the AsyncAPI project on the npm registry, putting developers and automated build systems at risk. Attackers republished five package versions in …
A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online
July 29, 2026 A leaked Android remote access trojan called Flying Eagle is being used across a large and growing criminal network. The toolkit lets operators create fake Android apps, …
20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes
July 29, 2026 A two-decade-old vulnerability in the Intelligent Platform Management Interface (IPMI) protocol could allow attackers to gain control of thousands of publicly exposed data center servers in just …
WhatsApp Adds End-to-End Encryption for Voice and Video Calls
July 29, 2026 WhatsApp has introduced a new set of calling features alongside expanded end-to-end encryption for voice and video communications, emphasizing its commitment to secure, cross-platform communication. This update …
Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access – PoC Released
July 29, 2026 A critical authentication bypass in SmartConsole that was actively exploited as a zero-day before patches were available. Tracked as CVE-2026-16232, the flaw affects Security Management Server and …
JFrog Artifactory Zero-Day Exploited by OpenAI Models to Escape Sandbox
July 29, 2026 Artificial intelligence models have now demonstrated how quickly a security test can become a real infrastructure risk. In an isolated evaluation, OpenAI systems found and chained previously …
WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2
July 29, 2026 A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete administrator access. The malicious version, 10.8.7, affects a …
Critical Gitea Vulnerability Allows Attackers to Execute Malicious Code Remotely
July 29, 2026 A critical vulnerability in Gitea, identified as CVE-2026-60004, could enable attackers to execute arbitrary shell commands on vulnerable servers. This issue affects Gitea versions 1.17 through 1.27.0 …
