The Daily Cyber
Archives
Search...
Log in
Subscribe
RabbitMQ OAuth Secret Leak Patched
July 13, 2026
RabbitMQ OAuth Secret Leak Patched RabbitMQ patched CVE-2026-57219, a flaw that could expose a broker's OAuth client secret from exposed management pages and...
Microsoft Defender RoguePlanet Patch
July 10, 2026
Microsoft Defender RoguePlanet Patch Microsoft patched CVE-2026-50656, the RoguePlanet elevation-of-privilege flaw in Microsoft Defender that could raise...
RoguePlanet Defender Patch Lands
July 9, 2026
RoguePlanet Defender Patch Lands Microsoft patched RoguePlanet (CVE-2026-50656), a Defender Malware Protection Engine flaw that could let a local attacker...
UniFi Connect Critical Command Injection Patch
July 8, 2026
UniFi Connect Critical Command Injection Patch Ubiquiti patched CVE-2026-50746, a critical UniFi Connect flaw that could let a network-access attacker run...
Gitea Docker Auth Bypass Probed
July 7, 2026
Gitea Docker Auth Bypass Probed Threat actors are probing Gitea Docker CVE-2026-20896, a critical reverse-proxy auth trust flaw that can let reachable...
Opera GX Mod Bug Leaked Data With CSS
July 6, 2026
Opera GX Mod Bug Leaked Data With CSS Opera patched an Opera GX mods flaw with no CVE that could let a malicious site silently install a GX Mod and use CSS...
npm Lookalike Packages Target Developer Secrets
July 3, 2026
npm Lookalike Packages Target Developer Secrets North Korea-linked malicious npm packages mimicked Rollup polyfill tooling to steal developer secrets and...
AI Agent Turns Langflow RCE Into Database Extortion
July 2, 2026
AI Agent Turns Langflow RCE Into Database Extortion Sysdig says JADEPUFFER used Langflow CVE-2025-3248 to drive an AI-agent ransomware chain against database...
Cursor DuneSlide Sandbox Escape
July 1, 2026
Cursor DuneSlide Sandbox Escape Two critical Cursor flaws, CVE-2026-50548 and CVE-2026-50549, could let hidden prompt injections escape the AI editor sandbox...
iOS AI Apps Leak Paid AI Access
June 30, 2026
iOS AI Apps Leak Paid AI Access Researchers found 282 iOS AI apps exposing paid LLM access through plaintext keys, replayable tokens, or open relays....
libssh2 Client-Side SSH Flaw Gets Public PoC
June 29, 2026
libssh2 Client-Side SSH Flaw Gets Public PoC A public PoC for CVE-2026-55200 highlights a critical libssh2 client-side flaw where a malicious SSH server...
PTC Windchill Web Shells Hit KEV
June 26, 2026
PTC Windchill Web Shells Hit KEV CISA added exploited PTC Windchill and FlexPLM CVE-2026-12569 to KEV after reports of JSP web shells on vulnerable systems....
Chrome Ad Blocker’s Hidden Permission Risk
June 25, 2026
Chrome Ad Blocker’s Hidden Permission Risk Researchers found the Chrome extension Adblock for YouTube, with 10M+ installs, had dormant script-injection...
Cordyceps CI/CD Bugs Expose Build Pipelines
June 24, 2026
Cordyceps CI/CD Bugs Expose Build Pipelines Researchers reported Cordyceps, a CI/CD workflow weakness that could let untrusted GitHub pull requests hijack...
GitHub Actions Adds a Checkout Guardrail
June 23, 2026
GitHub Actions Adds a Checkout Guardrail GitHub actions/checkout v7 now blocks common pwn-request checkouts that could let unreviewed fork PR code run with...
Squidbleed Leaks Proxy Requests
June 22, 2026
Squidbleed Leaks Proxy Requests Squidbleed (CVE-2026-47729) is a 29-year-old Squid Proxy heap over-read that can leak cleartext HTTP requests in shared proxy...
Salesforce Klue OAuth Token Abuse Exposes CRM Data
June 19, 2026
Salesforce Klue OAuth Token Abuse Exposes CRM Data Salesforce disabled Klue’s app integration after stolen access tokens were used to reach connected CRM...
Windows USB Clipper Worm Targets Crypto Wallets
June 18, 2026
Windows USB Clipper Worm Targets Crypto Wallets Microsoft detailed a Windows malware campaign that spreads through USB LNK shortcuts, swaps copied crypto...
Mastra npm packages hit by supply-chain compromise
June 17, 2026
Mastra npm packages hit by supply-chain compromise More than 140 Mastra npm packages were compromised through a hijacked contributor account and a malicious...
FortiSandbox Flaws Exploited in the Wild
June 16, 2026
FortiSandbox Flaws Exploited in the Wild Attackers are exploiting three Fortinet FortiSandbox flaws, including command-injection and path-traversal issues....
Newer archives
Older archives