iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

Today’s signal The Hacker News recently reported iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days. Published context: July 13, 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below - CVE-2026- ...

July 13, 2026 · 3 min · David Gomez

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Today’s signal The Hacker News recently reported Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions. Published context: July 11, 2026. Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user’s session. It has yet to b ...

July 11, 2026 · 3 min · David Gomez

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Today’s signal The Hacker News recently reported Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS. Published context: July 8, 2026. Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution. The list of vulnerabilities is as follows - CVE-2026-50746 (CVSS score: 10.0) - An improper access control vulnerability in UniFi Con ...

July 10, 2026 · 3 min · David Gomez

Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges

Today’s signal The Hacker News recently reported Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges. Published context: July 9, 2026. Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine (“mpengine.dll”), which provides scanning, detection, and cleaning capabil ...

July 9, 2026 · 3 min · David Gomez

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

Today’s signal The Hacker News recently reported BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA. Published context: July 7, 2026. BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are listed below - CVE-2026-40138 (CVSS score: 9.2) - A pre-authentication vulnerab ...

July 7, 2026 · 3 min · David Gomez

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case

Today’s signal The Hacker News recently reported U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case. Published context: July 4, 2026. A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money calls itself Kairos, but it may not be a ransomware gang at all. Krishnan found no si ...

July 6, 2026 · 3 min · David Gomez

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

Today’s signal The Hacker News recently reported SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation. Published context: July 2, 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deseria ...

July 5, 2026 · 3 min · David Gomez

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Today’s signal The Hacker News recently reported New Avalon Malware Framework Packs CrownX Ransomware Capabilities. Published context: July 3, 2026. Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that’s distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together The reason this matters is simple: buyers are paying attention to speed, operational resilience, and credible technical execution. A trending story can create awareness, but the business question is what a team should do with that attention. ...

July 4, 2026 · 3 min · David Gomez

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Today’s signal The Hacker News recently reported Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials. Published context: July 2, 2026. Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. “Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyb ...

July 3, 2026 · 3 min · David Gomez

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Today’s signal The Hacker News recently reported Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints. Published context: June 30, 2026. Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed a ...

July 1, 2026 · 3 min · David Gomez

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

Today’s signal The Hacker News recently reported Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer. Published context: June 30, 2026. An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability impacting the OpenID Connect (O The reason this matters is simple: buyers are paying attention to speed, operational resilience, and credible technical execution. A trending story can create awareness, but the business question is what a team should do with that attention. ...

June 30, 2026 · 3 min · David Gomez

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

Today’s signal The Hacker News recently reported Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse. Published context: June 29, 2026. A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025. Slovakian cybersecurity company ESET said it observed 35 distinct spear-phishing campaigns mounted by Gamaredon against new targets, with most of them taking place in the second half o ...

June 29, 2026 · 3 min · David Gomez