Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands

JetBrains has patched CVE-2026-63077, a critical TeamCity flaw that could let unauthenticated attackers execute server commands and compromise connected CI/CD pipelines. The post Critical TeamCity Flaw Could Let Unauthenticated... Read more »

Coca-Cola Confirms Data Theft as Fairlife Ransomware Attack Escalates

Coca-Cola has confirmed data was stolen in the ransomware attack on Fairlife after the Anubis gang published allegedly stolen files, escalating the incident. The post Coca-Cola Confirms Data Theft... Read more »

Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay

Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding environments. The post Cursor Quietly Patches High-Severity Git... Read more »

Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices

Apple’s latest iPhone, iPad and Mac updates patch 194 unique security flaws involving root access, kernel code execution and protected data. The post Apple Fixes 194 Security Flaws Across... Read more »

Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure

Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has... Read more »

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can... Read more »

JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover

JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked... Read more »

New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide

Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax... Read more »

Did an AI agent really break free and attack another company?

The reality of the AI-orchestrated cyber attack on Hugging Face is rather more complicated, and much more worrying, than it might appear at face value Read more »

U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added... Read more »
Subscribe to our Newsletter