vulnerability Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices A security researcher discovered an unpatched backdoor in Tenda firmware, granting attackers administrative access to Tenda devices. This vulnerability, tracked as CVE-2026-11405, allows attackers to bypass authenticatio… SecurityWeek · Jul 9, 2026 High CVE-2026-11405CVE-2026-13753backdoorunpatchedwebserver
threat-intel Critical Gitea Flaw Under Active Exploitation, Researchers Warn A critical vulnerability in Gitea’s reverse-proxy authentication mechanism is being actively exploited, allowing attackers to bypass authentication and gain unauthorized access to Gitea instances. The flaw, tracked as CV… SecurityWeek · Jul 7, 2026 Critical CVE-2026-20896vulnerabilityauthenticationgit
vulnerability Digi International PortServer TS, Digi One SP IA Digi International has issued a security advisory regarding critical vulnerabilities (CVE-2026-12948) in its PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices. These vulnerabilities allow an unauthentic… CISA Advisories · Jul 7, 2026 High CVE-2026-12352CVE-2026-12948xsscveweb-management
vulnerability CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The CERT Coordination Center has issued a warning about a hidden backdoor embedded in Tenda router firmware. This vulnerability, tracked as CVE-2026-11405, allows attackers to bypass password verification and gain full a… The Hacker News · Jul 7, 2026 High CVE-2026-11405routerbackdoorfirmware
threat-intel BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA BeyondTrust has released patches to address critical security vulnerabilities in its Remote Support and Privileged Remote Access products. These flaws, if exploited, could allow unauthenticated attackers to gain unauthor… The Hacker News · Jul 7, 2026 Critical CVE-2026-40138CVE-2026-40139CVE-2026-40140vulnerabilityauthenticationremote access
threat-intel Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure Threat actors have been actively probing a critical vulnerability in Gitea Docker images, exploiting a wildcard configuration that allows unauthenticated access to elevated user accounts. The vulnerability, discovered 13… The Hacker News · Jul 6, 2026 Critical CVE-2026-20896dockervulnerabilityauthentication
threat-intel When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website A sophisticated phishing campaign leveraging the Microsoft Identity Platform's Device Authorization Grant protocol is being used to compromise user accounts. Attackers are crafting emails that appear to be from legitimat… Securelist · Jul 6, 2026 High phishingdevice-code-phishingmicrosoft
threat-intel How We Added WebAuthn to a Browser-Based RDP Client This Palo Alto Unit 42 article details the development of a browser-based RDP client that supports WebAuthn redirection, allowing users to utilize security keys like YubiKeys during remote sessions. The team overcame sig… Palo Alto Unit 42 · Jul 2, 2026 Medium webauthnrdpbrowser
vulnerability ST Engineering iDirect iQ-Series Terminals ST Engineering iDirect has issued a security advisory regarding vulnerabilities in its iQ-Series Terminals, specifically versions through 4.5.2.1. These vulnerabilities allow unauthorized access to device information, in… CISA Advisories · Jul 2, 2026 High CVE-2026-38059CVE-2026-38057USapiauthenticationcsrf
threat-intel Massive Password Spray Campaign Targeting Azure CLI A massive password spray campaign targeting Microsoft 365 environments, specifically the Azure CLI, was observed by Huntress. The attacks, originating from AS32167 and linked to LSHIY LLC, resulted in the compromise of o… SecurityWeek · Jul 1, 2026 High CHHOUScredential spraymfaoauth ropc
vulnerability Critical SimpleHelp Vulnerability Exploited for Malware Delivery A critical vulnerability (CVE-2026-48558) in SimpleHelp RMM software allowed unauthorized access and subsequent malware deployment. The flaw, related to OpenID Connect authentication, enabled attackers to gain full techn… SecurityWeek · Jun 30, 2026 Critical CVE-2026-48558USoidcauthenticationmalware
threat-intel The Four Elevations of Effective Fraud Prevention This article discusses a multi-layered approach to fraud prevention, emphasizing the importance of monitoring across all customer touchpoints – from individual transactions to platform-wide activity. It advocates for col… BleepingComputer · Jun 25, 2026 High fraudaccount-takeoverauthentication
threat-intel ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories This article reports on several security vulnerabilities and trends, including a privacy-preserving protocol from Cloudflare, six vulnerabilities in the curl library, a critical security flaw in Hoppscotch allowing unaut… The Hacker News · Jun 25, 2026 High CVE-2026-8932CVE-2026-50160USKRsmart tvproxywareiot
threat-intel EVoke Systems Charging Station Management System This advisory details a vulnerability in the EVoke Systems Charging Station Management System (CSMS) due to a lack of proper authentication mechanisms in its WebSocket endpoints. Attackers could exploit this to gain unau… CISA Advisories · Jun 25, 2026 High CVE-2026-40702CVE-2026-50176CVE-2026-54479USwebsocketocppauthentication
vulnerability OHIF Viewers DICOM This advisory details a vulnerability in the OHIF Viewers DICOM framework, specifically versions up to v3.12.0, that allows attackers to steal authenticated user tokens via crafted links. The vulnerability stems from unc… CISA Advisories · Jun 25, 2026 High CVE-2026-12473USssrfdicomweboidc
vulnerability Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs Critical vulnerabilities were discovered in Ubiquiti UniFi devices, specifically CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, allowing for unauthorized access and command injection. While patches were released in… SecurityWeek · Jun 24, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910USvulnerabilitycommand injectionauthentication
threat-intel FortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist Persists The FortiBleed campaign, spearheaded by threat actors likely originating from Russia, has compromised over 430,000 FortiGate firewalls globally, resulting in the theft of more than 110 million credentials. Attackers util… Dark Reading · Jun 23, 2026 High USRUINcredential theftfirewallauthentication
vulnerability ABB Freelance Security Lock This report details a critical vulnerability in ABB’s Freelance Security Lock software, allowing attackers to bypass security measures and potentially gain access to underlying operating system functions. The vulnerabili… CISA Advisories · Jun 23, 2026 Critical CVE-2025-7064WOkeyboardsecuritybypass
vulnerability Hubbell Aclara Metrum Cellular Web Interface This CISA advisory details a vulnerability in Hubbell Aclara Metrum Cellular Web Interface software, specifically versions prior to 2.1.0.105. The flaw allows unauthorized access to critical device settings, potentially… CISA Advisories · Jun 23, 2026 High CVE-2026-1840USfirmwareauthenticationcritical infrastructure
threat-intel Russian Initial Access Broker Behind FortiBleed Campaign A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls globally as part of the FortiBleed campaign, harvesting credentials and selling access to other malicious actors. The campaign utilizes… SecurityWeek · Jun 23, 2026 High USGBNLcredential harvestingfirewallsupply chain