July 2, 2026 A proof-of-concept vulnerability chain in ChatGPT that combined a guardrail bypass with a path traversal flaw, potentially allowing attackers to access restricted system files such as /etc/passwd …
900+ Oracle E-Business instances Exposed Online Amid Active Vulnerability Exploitation
July 2, 2026 More than 900 Oracle E‑Business Suite instances have been found exposed on the public internet. At the same time, attackers actively exploit a critical vulnerability in the …
Hackers Use Legitimate VLC Executable and Malicious libvlc.dll to Deploy ValleyRAT
July 2, 2026 Cybercriminals have found a clever way to slip past security defenses by hiding malware inside a program most people trust without a second thought. Researchers have uncovered …
Cisco Catalyst Center Vulnerability Allows Remote Attackers to Read Arbitrary Files
July 2, 2026 Cisco has disclosed a high-severity vulnerability in its Catalyst Center platform that could allow unauthenticated remote attackers to read arbitrary files from affected systems. The issue, tracked …
Hackers Use Mapbox Dead-Drop C2 and Python RAT to Target Vulnerability Researchers
July 2, 2026 Security researchers have uncovered a long-running campaign that turns trusted proof-of-concept exploits into weapons against the very people who study vulnerabilities for a living. The operation, tracked …
Critical JetBrains Vulnerabilities Enable Authentication Bypass and Code Execution Attacks
July 2, 2026 JetBrains has released security updates for a cluster of critical vulnerabilities that enable authentication bypass, account takeover, and remote code execution (RCE) across its on‑premise ecosystem, including …
Hackers Disable Defender, Sysmon, and WAF Before Dumping Credentials With Mimikatz
July 2, 2026 Hackers have found a new way to blind security teams before stealing passwords, and the technique is as thorough as it is alarming. A threat actor recently …
CISA Warns of Microsoft SharePoint Server Code Execution Vulnerability Exploited in Attacks
July 2, 2026 CISA has added a newly disclosed Microsoft SharePoint Server vulnerability, tracked as CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is actively being …
Browser-Only Ransomware Abuses Chrome File System Access API to Encrypt Android Photos
July 2, 2026 A new ransomware technique can now run entirely inside a web browser, with no app installation or root access required. It targets Android photo directories by abusing …
Multiple ClamAV Vulnerabilities Allow Remote Attacker to Cause a DoS Condition
July 2, 2026 Multiple high-severity vulnerabilities in Cisco’s ClamAV engine allow remote attackers to crash the antivirus scanning process, causing a denial-of-service (DoS) on affected Cisco Secure Endpoint Connector deployments. …
