July 2, 2026 A newly disclosed CitrixBleed-class vulnerability in Citrix NetScaler appliances came under active exploitation less than a day after public disclosure, with decoy infrastructure operator Lupovis confirming a …
DHS Confirms Breach of Information-Sharing Network Platform HSIN
July 2, 2026 The Department of Homeland Security has confirmed that hackers breached the Homeland Security Information Network (HSIN), a sensitive but unclassified platform relied upon by federal, state, local, …
ChatGPT File Download Flow Vulnerability Could Be Abused to Access System Files
July 2, 2026 A proof-of-concept vulnerability chain in ChatGPT that combined a guardrail bypass with a path traversal flaw, potentially allowing attackers to access restricted system files such as /etc/passwd …
900+ Oracle E-Business instances Exposed Online Amid Active Vulnerability Exploitation
July 2, 2026 More than 900 Oracle E‑Business Suite instances have been found exposed on the public internet. At the same time, attackers actively exploit a critical vulnerability in the …
Hackers Use Legitimate VLC Executable and Malicious libvlc.dll to Deploy ValleyRAT
July 2, 2026 Cybercriminals have found a clever way to slip past security defenses by hiding malware inside a program most people trust without a second thought. Researchers have uncovered …
Cisco Catalyst Center Vulnerability Allows Remote Attackers to Read Arbitrary Files
July 2, 2026 Cisco has disclosed a high-severity vulnerability in its Catalyst Center platform that could allow unauthenticated remote attackers to read arbitrary files from affected systems. The issue, tracked …
Hackers Use Mapbox Dead-Drop C2 and Python RAT to Target Vulnerability Researchers
July 2, 2026 Security researchers have uncovered a long-running campaign that turns trusted proof-of-concept exploits into weapons against the very people who study vulnerabilities for a living. The operation, tracked …
Critical JetBrains Vulnerabilities Enable Authentication Bypass and Code Execution Attacks
July 2, 2026 JetBrains has released security updates for a cluster of critical vulnerabilities that enable authentication bypass, account takeover, and remote code execution (RCE) across its on‑premise ecosystem, including …
Hackers Disable Defender, Sysmon, and WAF Before Dumping Credentials With Mimikatz
July 2, 2026 Hackers have found a new way to blind security teams before stealing passwords, and the technique is as thorough as it is alarming. A threat actor recently …
CISA Warns of Microsoft SharePoint Server Code Execution Vulnerability Exploited in Attacks
July 2, 2026 CISA has added a newly disclosed Microsoft SharePoint Server vulnerability, tracked as CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is actively being …
