Jul 28, 2026
7 itemsDaily Cyber Digest — July 28, 2026
Tengu botnet, NightLedger backdoor, Fastjson 1.x zero-day, CISA KEV additions, and more from July 28, 2026.
Tag archive
All visible posts matching this normalized tag.
Jul 28, 2026
7 itemsTengu botnet, NightLedger backdoor, Fastjson 1.x zero-day, CISA KEV additions, and more from July 28, 2026.
Jul 13, 2026
5 itemsFive high-signal cyber developments from July 11-13, 2026: Joomla zero-days in CISA KEV, exposed Evilginx ops, a jscrambler npm infostealer, Pakistan police portal espionage, and unpatched AI-infra flaws.
Jul 11, 2026
5 itemsJuly 10, 2026 roundup: AI-driven patch pressure, a 200+ GitHub malware network, active Django SQLi, HalluSquatting, and a malicious Injective npm SDK.
NEWS
Zimbra 10.1.19 patches a critical stored XSS in the Classic Web Client that can execute malicious scripts when a victim opens a crafted email.
Jul 10, 2026
5 itemsJuly 9 roundup covering Defender patching, Helix SharePoint extortion, proxy malware, npm hardening, and open-source sabotage risk.
NEWS
Ubiquiti patched 25 UniFi ecosystem vulnerabilities, including a CVSS 10.0 UniFi Connect command-injection flaw.
Jul 09, 2026
6 itemsJuly 8 brought exploited vulnerability updates, UniFi critical patches, Langflow credential-harvesting activity, and fresh research on ORB and AI-agent abuse.
NEWS
BeyondTrust fixed four flaws in Remote Support and PRA, including two pre-auth auth-bypass bugs (CVE-2026-40138/40139, CVSS 9.2) letting attackers seize appliances.
Jul 07, 2026
6 itemsCritical remote-access auth bypasses, a 16-year Linux KVM VM-escape flaw, Cisco ISE RCE, Chrome and Teams threats lead the day.
NEWS
CERT/CC warned that several Tenda firmware builds include an undocumented authentication backdoor that can grant full router web-admin access.
NEWS
CISA added CVE-2026-45659 in Microsoft SharePoint to its KEV catalog after active exploitation, and Microsoft’s May 2026 fixes cover SharePoint 2016, 2019, and Subscription Edition.
Jul 02, 2026
5 itemsSource-backed July 1 digest covering active exploitation, critical enterprise patching, AI/browser attack research, and fake-PoC supply-chain abuse.
NEWS
CISA's June 30 advisory for StoneFly Storage Concentrator flags hard-coded credentials, command injection, SQL injection, and XSS with root-level impact across SC and SCVM.
Jul 01, 2026
6 itemsMicrosoft patches 200 flaws including 6 zero-days; CISA adds SimpleHelp RCE to KEV; INC ransomware hits 830+ victims; Qilin attacks Transcore; FIFA 2026 fraud infrastructure pre-positioned.