Security Unpatched Backdoor in Tenda Routers Gives Attackers Full Admin Access The TeamJuly 9, 20260 There’s an undocumented backdoor in Tenda firmware, and there’s no fix for it. Tracked as CVE-2026-11405, the vulnerability lives in…
Security Fake 7-Zip Installers Are Turning PCs Into Proxy Nodes for Criminals The TeamJuly 9, 20260 Download 7-Zip from the wrong site and your computer becomes a pawn in a proxy scheme. Researchers at Infoblox uncovered…
Security GhostApproval: Six AI Coding Assistants Vulnerable to Symlink Attack The TeamJuly 9, 20260 Wiz researchers found a nasty trick that works against six popular AI coding assistants. A malicious repo can use symbolic…
Security Closing the Blind Spots in AI Identity Security The TeamJuly 9, 20260 You can’t secure what you can’t see. That’s the problem with AI agents — they get created, do their job,…
Security Critical Bug in GitHub Agentic Workflows Lets Attackers Steal Private Repo Data The TeamJuly 9, 20260 A nasty prompt injection vulnerability in GitHub Agentic Workflows could let unauthenticated attackers siphon data from private repositories. No credentials…
Security China-Linked APT Expands Backdoor Arsenal With LongLeash, DogLeash, JarLeash The TeamJuly 8, 20260 A China-linked APT group has been building out its toolset, adding three new backdoors to an already active espionage campaign….
Security Mount Royal University Confirms Breach, Hackers Demand $1.9M Ransom The TeamJuly 8, 20260 Mount Royal University in Calgary confirmed hackers broke into its network, stole data, and wiped file storage systems. The attack…
Security China-linked UAT-7810 expands ORB network with new LONGLEASH malware The TeamJuly 8, 20260 A Chinese threat actor tracked as UAT-7810 keeps building out its relay network. The group is actively refining custom malware…
Security GitHub Copilot refuses harmful requests in chat — then writes them in code The TeamJuly 8, 20260 Ask GitHub Copilot to do something dangerous in its chat box, and it’ll say no. Break that same request into…
Security Fake Paysafe and Skrill SDKs on npm and PyPI are stealing developer credentials The TeamJuly 8, 20260 Someone published 17 fake packages on npm and PyPI posing as Paysafe, Skrill, and Neteller SDKs. Their real job? Stealing…