Aggregator
Weekly Threat Bulletin – July 22nd, 2026
Exim security advisory (AV26-737)
От гекконов роботы получили цепкие поверхности, от змей — гибкое тело, от рыб — волнообразные движения. Так работает биоинспирированная робототехника нового поколения
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Progress security advisory (AV26-736)
Submit #860587: facil.io <= 0.7.58 Improper Limitation of a Pathname to a Restricted Directory [Accepted]
RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
A new Linux vulnerability dubbed “RefluXFS” is a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in Enforcing mode. The vulnerability tracked as CVE-2026-64600 uncovered by Qualys Threat Research Unit (TRU) exploits […]
The post RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access appeared first on Cyber Security News.
Создан ИИ, который может стать основой для виртуальных клеток — цифровых копий живых тканей
Mitel security advisory (AV26-734)
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users
A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply visited a malicious webpage no clicks, downloads, or credential theft required. Security researchers at Guardio Labs uncovered the flaw, dubbed “HermeticReader,” and officially tracked as CVE-2026-48294 with a […]
The post Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users appeared first on Cyber Security News.
French Parliament greenlights social media ban for under-15s
n8n security advisory (AV26-733)
ISC BIND security advisory (AV26-732)
Один клик по ссылке — и ваша переписка в WhatsApp как на ладони. Спасибо, Adobe Acrobat
ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
ASUS has released critical security updates to address a high-severity router vulnerability that could allow remote attackers to execute arbitrary commands on affected devices. The flaw, tracked as CVE-2026-13385, impacts multiple ASUS router firmware branches, including the widely deployed 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. According to the ASUS Product Security Advisory, the vulnerability stems from […]
The post ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution appeared first on Cyber Security News.
A Hidden Line of Website Text Can Turn AWS Kiro Into a Remote Code Execution Tool
A recently disclosed vulnerability in AWS Kiro, an AI-powered Integrated Development Environment (IDE), reveals how a hidden line of text on a webpage can be exploited for remote code execution on a developer’s machine, bypassing the platform’s security model. Kiro operates on a “human-in-the-loop” principle, requiring user approval for potentially dangerous actions like executing shell […]
The post A Hidden Line of Website Text Can Turn AWS Kiro Into a Remote Code Execution Tool appeared first on Cyber Security News.
Malware is targeting AI tools in software development environments
The worm blends in with thousands of other commands occurring daily in any given environment, yet its intent and origins remain unknown.
The post Malware is targeting AI tools in software development environments appeared first on CyberScoop.
Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results
JFrog Security Research has disclosed a precision supply-chain attack in which a typosquatted NuGet package, Newtonsoftt.Json.Net, impersonated the ubiquitous Newtonsoft.Json library while secretly rigging game outcomes at online betting operator Digitain. Unlike typical info-stealers that harvest credentials indiscriminately, this trojan functions as a fully operational JSON library for every host except its single intended target. […]
The post Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.