Risk & Resilience

Wiz Reveals GitHub Actions Workflow Vulnerability In Snowflake Repository

Wiz has disclosed a GitHub Actions workflow injection flaw in a Snowflake public repository that could allow crafted GitHub issues to trigger command execution and expose internal Jira credentials.

Critical Forminator Plugin Vulnerability Puts Thousands Of WordPress Sites At Risk

A critical vulnerability in the Forminator WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute remote code on vulnerable websites.

Researchers Reveal Unpatched Unisoc Android Kernel Exploit Through VoLTE Video Calls

Security researchers have disclosed a two stage exploit chain affecting Unisoc chipsets that can achieve Android kernel access through VoLTE video calls with no vendor patch currently available.

Evooo1Bot Malware Targets Linux Devices Through Multiple Known Vulnerabilities

Fortinet researchers have identified the Evooo1Bot Linux botnet, which exploits multiple known vulnerabilities to compromise internet facing devices and convert them into SOCKS5 proxy nodes.

VMware vCenter Vulnerability Exploited In Global Campaign Linked To Suspected China Nexus Threat Actor

Researchers have linked active exploitation of VMware vCenter vulnerability CVE 2026 59310 to a suspected China nexus threat actor deploying backdoors, reverse SSH tools and Babuk derived ransomware.

CTM360 Report Reveals Browser In Browser Recruitment Phishing Campaign Targeting Enterprise Accounts

CTM360 has uncovered a large scale recruitment phishing campaign using Browser In Browser credential traps, fake interview pages and live MFA relay attacks to target enterprise accounts.

Cohesity Webinar Highlights Microsoft 365 Backup And Cyber Resilience Strategies

Cohesity will host a webinar on August 27 to discuss Microsoft 365 data protection, immutable backups, encryption and isolated storage for improving cyber resilience.

Critical SAP Commerce Cloud Flaw CVE 2026 58231 Draws Early Exploitation Activity

Security researchers have observed exploitation attempts targeting SAP Commerce Cloud vulnerability CVE 2026 58231 only days after SAP released a patch for the critical remote code execution flaw.

Updated CoolClient Malware Uses Signed Windows Rootkit For Advanced Stealth

Kaspersky has identified a new CoolClient malware variant linked to Mustang Panda that deploys a signed Windows kernel rootkit to hide malicious activity and strengthen persistence on compromised systems.

Apple Issues Spyware Threat Notifications To Users Across 110 Countries

Apple has issued new spyware threat notifications to users in 110 countries, warning that mercenary spyware attacks continue to target journalists, activists, politicians, diplomats and other high risk individuals.

Active Exploitation Attempts Detected Against Unpatched GeoServer SQL Injection Flaw

Security researchers warn that a newly disclosed GeoServer zero day SQL injection vulnerability is being actively targeted and could lead to remote code execution on vulnerable systems.

Jewelbug Expands Cyber Espionage And Cryptocurrency Fraud Through XG Web Platform

Broadcom researchers reveal China linked Jewelbug using the XG Web platform to conduct cyber espionage against governments and militaries while operating cryptocurrency fraud campaigns.

Recent articles

spot_img