Critical Gitea Docker Auth Bypass (CVE-2026-20896) Under Active Exploitation — One Header Grants Full Admin Access
Security researchers have confirmed active exploitation of CVE-2026-20896, a critical authentication bypass vulnerability (CVSS: 9.8) affecting Gitea official Docker images through version 1.26.2. The flaw allows an attacker to impersonate…
BeyondTrust Patches Critical Pre-Auth Bypass (CVE-2026-40138, CVSS 9.2) in Remote Support and Privileged Access Appliances
BeyondTrust has disclosed a critical pre-authentication vulnerability — CVE-2026-40138 (CVSS v4: 9.2) — affecting its Remote Support (RS) and Privileged Remote Access (PRA) appliances. The flaw stems from improper validation…
GhostLock (CVE-2026-43499): 15-Year Linux Kernel Flaw Gives Unprivileged Users Root — PoC Published
Security researchers at Nebula Security’s VEGA team have disclosed GhostLock (CVE-2026-43499), a use-after-free vulnerability in the Linux kernel’s real-time mutex (futex priority-inheritance) code that has been sitting unpatched for approximately…
ShinyHunters Publishes 26 Million MSG Entertainment Records — Facial Recognition and Threat Assessment Data Exposed
ShinyHunters, one of the most prolific data extortion groups operating today, has published 45 gigabytes of stolen data from Madison Square Garden Entertainment Corp. (MSG Entertainment) after the company refused…
OpenAI Launches GPT-5.6 Series — Sol, Terra, and Luna Now Available to the Public
OpenAI made its most significant model launch of the year on July 9, 2026, releasing the GPT-5.6 series to the general public. The series consists of three models — Sol,…
FortiBleed Credential-Harvesting Campaign Directly Linked to INC Ransom and Lynx Ransomware Groups
Summary The FortiBleed credential-harvesting campaign, which compromised over 430,000 Fortinet firewall devices, has been directly linked to the INC Ransom and Lynx ransomware groups. Researchers identified an initial access broker…
EU Unveils Action Plan on AI and Cybersecurity — Pre-Market Model Testing and a European AI Defense Blueprint
Summary The European Commission on July 7 unveiled a comprehensive “Action Plan on Cybersecurity and Artificial Intelligence” to address both the risks and opportunities of advanced AI in cybersecurity. The…
“DuneSlide” Flaws in Cursor AI IDE Allow Prompt Injection to Escape Sandbox and Execute Arbitrary Commands
Summary Two critical vulnerabilities in the Cursor AI code editor, collectively dubbed “DuneSlide” by researchers at Cato AI Labs, allow a single prompt injection to escape the editor’s safety sandbox…
Assail Launches Sidewinder — A Self-Healing Autonomous Red Team AI That Audits Its Own Work
Summary Offensive security startup Assail has launched Sidewinder, a complete redesign of its Ares platform that operates as an autonomous red team AI capable of auditing its own work, fixing…
UK’\”s NCSC Unveils “Cyber Shield” — A National-Scale Agentic AI Defense Capability
Summary Britain’s National Cyber Security Centre (NCSC) has laid out plans for what it calls “a national scale, sovereign defense capability” powered by agentic AI systems. Dubbed “Cyber Shield,” the…
