July 11, 2026 CISA has published a candid after-action account revealing that a contractor accidentally exposed the agency’s own AWS GovCloud credentials and Infrastructure-as-Code repositories in a personal, public GitHub …
Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds
July 11, 2026 A critical flaw in how Dell stores BIOS administrator and user passwords allows full password recovery from a flash dump in milliseconds, with no brute force required. …
281 Popular VPN Apps from the Google Play Store Leak Sensitive Data, Transfer Data Unencrypted
July 11, 2026 A new security study has found serious privacy and security issues in 281 popular Android VPN applications available on the Google Play Store. Researchers discovered that dozens …
Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat
July 10, 2026 Progress Software has issued an urgent advisory instructing customers running on-premises ShareFile Storage Zone Controllers to immediately power down the servers hosting these components, citing a “credible …
One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers
July 10, 2026 Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. …
Top 10 Best Unified Threat Management (UTM) Solutions in 2026
If you need one appliance that handles firewalling, intrusion prevention, VPN, antivirus, and web filtering without a security team to run it, Fortinet FortiGate is our top UTM pick for …
Hackers Can Go From CitrixBleed 2 Exploitation to Ransomware in Under an Hour
July 10, 2026 A critical Citrix flaw is giving intruders a fast route from an internet-facing gateway to a ransomware event. The activity centers on CitrixBleed 2, tracked as CVE-2025-5777, …
Malicious Windows Shortcuts Use PowerShell and Node.js to Enable Remote Code Execution
July 10, 2026 A malicious Windows shortcut is being used to turn a routine download into a full remote-code-execution foothold. The campaign begins with convincing booking-themed spam and steers victims …
GNU Guix Vulnerabilities Allow Remote Privilege Escalation via Malicious Binary Substitutes
July 10, 2026 GNU Guix has disclosed four serious security vulnerabilities affecting its package substitution and channel-management features. Three flaws in the guix substitute utility can enable remote privilege escalation, …
Hackers are Turning AI Gateways as Attack Surfaces to Compromise Enterprise Networks
July 10, 2026 AI gateways are increasingly being targeted as organizations connect generative AI applications to cloud services such as Amazon Bedrock. These gateways sit between users, business applications, and …
