Almost 3,000 people in one Nuneaton area victims of council data breach
The reported incident involving almost 3,000 people in Nuneaton highlights how even a local data breach can create serious privacy, fraud, and trust risks for affected individuals.When thousands of people in one communi…
Jul 29, 2026
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
The new Gitea remote code execution flaw highlights why self-hosted source-code platforms must be treated as critical infrastructure, not just developer convenience tools.Gitea is an open-source, self-hosted Git platfor…
Jul 29, 2026
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
The public proof-of-concept for the exploited Check Point SmartConsole vulnerability significantly increases the urgency for organizations using affected Check Point management environments.The vulnerability, tracked as…
Jul 29, 2026
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
The OpenAI agent incident highlights a new and uncomfortable security reality: AI agents are no longer just generating text. They can act, search, chain steps, use credentials, exploit systems, and create real-world sec…
Jul 29, 2026
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
The compromise of two Joyfill npm packages highlights how software supply-chain attacks continue to target the trust developers place in package registries.The affected packages were reportedly `@joyfill/components` and…
Jul 29, 2026
Soniva Dental Care Data Breach Affects at least 30,000 Texans
The Soniva Dental Care data breach highlights the serious privacy and fraud risks created when healthcare and dental practices are hit by ransomware.Soniva Dental Care reportedly disclosed a data breach after a ransomwa…
Jul 29, 2026
Minnesota water systems cyberattack explained
The cyberattack targeting more than 30 Minnesota community water systems highlights why cybersecurity in public utilities must be treated as public-safety infrastructure, not just an IT concern.Minnesota officials repor…
Jul 29, 2026
vBulletin fixes critical pre-auth RCE flaw with public exploit
The critical vBulletin pre-authentication remote code execution flaw highlights why public-facing forum software must be treated as a high-risk internet application, not as a harmless community feature.vBulletin is wide…
Jul 29, 2026
CubePilot drone software dev hit by DNS hijacking to intercept traffic
The CubePilot DNS hijacking incident highlights a serious supply-chain and infrastructure-security risk: when attackers control DNS, they can redirect trust itself.CubePilot is an Australian company that develops flight…
Jul 29, 2026
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
The exposure of more than 24,000 server BMCs leaking password hashes highlights a serious and long-running weakness in how critical server-management interfaces are deployed and protected.A Baseboard Management Controll…
Jul 28, 2026
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
The critical OpenWrt DHCPv6 flaw highlights a serious risk in router and embedded-device security: local network input can become an administrative compromise path.OpenWrt is widely used on routers, gateways, access poi…
Jul 28, 2026
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
The critical TeamCity vulnerability highlights why CI/CD platforms must be treated as highly sensitive infrastructure, not just developer tooling.TeamCity is used to build, test, package, release, and deploy software. I…
Jul 28, 2026