July 13, 2026 The Cybersecurity and Infrastructure Security Agency (CISA) has added two high-risk Joomla extension flaws to its Known Exploited Vulnerabilities (KEV) Catalog. Both vulnerabilities allow unrestricted file uploads, …
iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation
July 13, 2026 A digital forensics investigation from Belkasoft into an iPhone and a damaged MacBook has helped secure the conviction of Jason Cunningham, a rent-to-rent property operator who defrauded …
Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website
July 13, 2026 A critical security vulnerability has been discovered in the widely used WordPress OAuth Single Sign–On (SSO (OAuth Client) plugin developed by miniOrange, exposing millions of WordPress websites …
VEXAIoT Multi-Agent System Automates IoT Reconnaissance and Exploit Execution
July 13, 2026 Security researchers have introduced VEXAIoT, an AI-powered multi-agent framework designed to automate vulnerability discovery and exploit execution against Internet of Things environments. The research shows how large …
Armored Likho APT Uses AI-Generated Loaders to Deploy BusySnake Stealer Against Government Targets
July 13, 2026 Armored Likho has launched a phishing campaign that uses AI-generated loaders to deploy the newly identified BusySnake Stealer. The operation has targeted government agencies and electrical power …
Hackers Compromised jscrambler With 15,800+ Weekly Downloads to Attack Developers
July 13, 2026 A supply chain attack on the jscrambler npm package, a JavaScript code-protection tool with over 15,800 weekly downloads, involved malicious versions that silently deployed native malware on …
Anthropic Extends Claude Fable 5 Access From July 12 to July 19
July 13, 2026 Anthropic has extended promotional access to Claude Fable 5 until July 19, 2026, giving eligible paid subscribers more time to use the company’s newest AI model at …
Hackers Weaponize Real Academic Event Materials to Infect Researchers With RokRAT
July 13, 2026 A targeted phishing campaign is using genuine academic event details to trick researchers into opening malware. The operation delivers a RokRAT variant through a fake document package …
One Misconfigured Python HTTP Server Exposed Three Active Campaigns from Attackers
July 13, 2026 A forgotten web server can become a window into a criminal operation. In this case, a Python HTTP service left exposed on a virtual private server revealed …
Hackers Can Exploit Motorola MR2600 Firmware Update Process to Gain Code Execution
July 13, 2026 A newly disclosed unauthenticated remote code execution vulnerability in Motorola MR2600 Wi-Fi routers allows attackers on the local network to upload and install a malicious firmware image …
