July 21, 2026 Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches …
Hackers Could Turn AI Training Jobs Into Weapons Against the Power Grid
July 21, 2026 A new research threat called Bit2Watt shows how AI training jobs could be abused to disrupt the power systems that support data centers. Rather than installing malware …
The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide
Why identity fragmentation is the blind spot behind most breaches—and what a platform approach changes The Identity Problem Hiding in Plain Sight Identity is at the centre of nearly every …
Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems
July 21, 2026 A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks. The operation relies on familiar Windows components …
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware
Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf …
Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers
July 21, 2026 A new open-source project, Furtex, has emerged as a Linux-focused post-exploitation and evasion research toolkit for authorized security researchers and red-team operators. The project combines raw io_uring …
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
July 20, 2026 A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a …
Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon
July 20, 2026 Windows defenders are facing a new way for attackers to hide activity after gaining administrator access. The technique abuses Windows bind links, a legitimate feature that redirects …
Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details
A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely …
Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
A massive data breach has hit Paidwork, a popular gig economy platform, exposing sensitive banking and personal information belonging to more than 23 million users worldwide. The incident, first surfacing …

