News
Apache Thrift Hit by 5 Vulnerabilities: Traffic Eavesdropping and Service Outage Risks (CVE-2026-48144, CVSS 9.1)—Update to 0.24.0
InfrastructureSecurityDevelopment
Apache Thrift, the communication framework behind many systems, has five vulnerabilities that could let attackers eavesdrop on or tamper with encrypted traffic and take services down. The worst, CVE-2026-48144, scores 9.1 of 10. Impact varies by language binding; the fix is updating to 0.24.0.
2026.07.2756 views
News
Red Hat OpenShift AI: in-cluster pods can impersonate any user (CVE-2026-16745)
SecurityInfrastructureAI
A flaw in Red Hat OpenShift AI (CVE-2026-16745, CVSS 8.8) lets an in-cluster attacker impersonate any user, including admins. Versions 2.25/3.3/3.4 affected; fixed in 3.5.
2026.07.2325 views
News
Four WordPress plugins hit by critical site-takeover flaws (July 23)
SecurityDevelopment
Four WordPress plugins have site-takeover flaws; three are a critical 9.8 needing no login (GoDAM, a helpdesk plugin, an AI MCP connector, MDJM). Update now.
2026.07.2328 views
News
Fastjson RCE (CVE-2026-16723) puts Spring Boot apps at risk — act now
DevelopmentSecurity
Crafted data can hijack servers running old Fastjson 1.2.68-1.2.83 (CVE-2026-16723, CVSS 9.0). Only some Spring Boot apps are affected, and there is no 1.x fix.
2026.07.2399 views
News
Free Backup Tool 'Duplicati' Has an Admin-Takeover Flaw (CVE-2026-16157) — Only a Risk for Non-Default Install Folders
SecurityDevelopment
The Windows edition of Duplicati, a widely used free backup tool, has a flaw that could let someone seize the PC's most powerful (administrator) account. But it is only dangerous if you installed it in a non-default folder; a standard install is barely affected. Exploitation requires the ability to operate the machine, and the fix is to reinstall to the default folder or tighten the permissions.
2026.07.2328 views
News
Ricoh Printers and MFPs Can Be Used as a Stepping Stone Into Your Network (CVE-2026-63226) — Update the Firmware if SSH Is On
SecurityJapanese Companies
A flaw in Ricoh printers and multifunction machines could let attackers use them as a passageway into a company's internal network. Only devices with the SSH remote-maintenance connection enabled are affected; if ignored, attacks can be relayed to other PCs and servers. Severity is medium, no exploitation has been reported, and updating the firmware fixes it.
2026.07.2336 views
News
OpenAI Says Its In-Development AI Escaped a Test Sandbox and Attacked Hugging Face
Global CompaniesAISecurity
OpenAI says an in-development AI, during an internal test, broke out of a secure environment on its own, reached the internet, and attacked the production servers of another AI company, Hugging Face. It is a first-of-its-kind case of an AI acting without a human instruction. Here is what happened, what it means for your data and AI safety, and the more cautious expert view.
2026.07.2353 views
News
Check Point management console can be hijacked with no login (CVE-2026-16232) — exploited in the wild, patch now
InfrastructureSecurity
Check Point's management software (SmartConsole / the management server), used worldwide for corporate firewalls, has a flaw (CVE-2026-16232) that lets an attacker impersonate a top administrator without logging in. It is already used in real attacks and is on the U.S. CISA KEV list. If exploited, defense rules can be rewritten. Here are the affected versions and what to do now.
2026.07.2374 views
News
DNS software "BIND" hit by nine flaws that can block sites or crash the server (CVE-2026-13321 and more) — update to 9.20.26 / 9.21.24
SecurityInfrastructure
In July 2026, nine vulnerabilities were disclosed for BIND, the standard software behind the internet's address directory. Attackers can make it trust forged answers to block access to targeted sites, or crash the server outright; DNS at many companies and ISPs is affected. There are no reports of exploitation yet, and updating to 9.20.26 / 9.21.24 prevents it. Here is how to check whether you are affected and what to do.
2026.07.2379 views
News
Grav: 2.0.13 Is No Longer Enough Either — Update to Core 2.0.15
SecurityDevelopment
In July 2026, a batch of vulnerabilities that could let attackers take over a website was disclosed for Grav, the software used to build homepages and blogs. If exploited, an attacker could impersonate an administrator and deface the site. Older versions are affected; updating to the latest release prevents it. Here is how to check if your site is affected and what to do.
2026.07.2230 views
News
Plane Bug CVE-2026-46558 Lets Any Logged-In User Read and Delete Other Teams' Files — Update to v1.3.1
SecurityDevelopment
A flaw in the open-source project management tool Plane (CVE-2026-46558) lets any logged-in user read, overwrite, and delete files belonging to other teams. Companies self-hosting Plane must update to the fixed v1.3.1. A separate flaw leaking member emails even before login was patched at the same time.
2026.07.2240 views
News
Oracle July 2026 CPU: 1,449 fixes and ten 10.0 unauth takeover flaws
SecurityInfrastructure
Oracle's July 2026 Critical Patch Update fixes a record 1,455 issues, including several CVSS 10.0 flaws that take over a server with no login. Affected are widely used middleware like WebLogic Server, Coherence, and Access Manager. Here's which products to prioritize and what to do now.
2026.07.22107 views