vulnerability Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE Next.js has released security patches to address two critical vulnerabilities. The first, a Windows path traversal flaw, allows unauthenticated remote code execution when processing specially crafted AVIF images. The second, a heap buffer overflow in the libheif C library used for AVIF image optimization, also leads to… The Hacker News · 3d ago High CVE-2026-75604avifrcelibheif
ransomware The Gentlemen are knocking: сustom backdoors and evolving tactics This report details the activities of "The Gentlemen," a ransomware-as-a-service (RaaS) group that has been aggressively targeting large corporations and critical infrastructure since early 2026. The group employs sophis… Securelist · Jun 29, 2026 High USransomware-as-a-servicereconnaissancelateral movement
threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia