⤷ Title: Claude Fable 5 Auto-Downgrades Tasks It Deems Too Simple Logs Prove It
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 10:35:16 +0000
════════════════════════
⌗ Tags: #Technology #AI Classifier #Anthropic #Claude Code #Claude Fable 5 #Claude Opus 4.8 #LLM Subscription #Model Downgrade
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 10:35:16 +0000
════════════════════════
⌗ Tags: #Technology #AI Classifier #Anthropic #Claude Code #Claude Fable 5 #Claude Opus 4.8 #LLM Subscription #Model Downgrade
Daily CyberSecurity
Claude Fable 5 Auto-Downgrades Tasks It Deems Too Simple Logs Prove It
Claude Fable 5 is back online. Developers using Claude Code can access the model through their existing subscription until July 7. However, there is a significant catch. Usage is capped at 50 perc…
⤷ Title: Lazarus-Linked npm Malware Masquerades as Rollup Polyfills
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 09:22:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto wallet theft #JFrog #Lazarus #malicious npm packages #North Korea #npm malware #Rollup polyfill #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 09:22:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto wallet theft #JFrog #Lazarus #malicious npm packages #North Korea #npm malware #Rollup polyfill #supply chain attack
Daily CyberSecurity
Lazarus-Linked npm Malware Masquerades as Rollup Polyfills
At a glance Actor Suspected North Korean Lazarus-linked group (attribution by TTP similarity) Activity npm supply chain attack using lookalike Rollup polyfill packages Targets JavaScript developer…
⤷ Title: Silent Swap Crypto Clipper Hides in Google Notes Extension
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 08:11:05 +0000
════════════════════════
⌗ Tags: #Malware #Crypto Clipper #EtherHiding #malware #Silent Swap
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 08:11:05 +0000
════════════════════════
⌗ Tags: #Malware #Crypto Clipper #EtherHiding #malware #Silent Swap
Daily CyberSecurity
Silent Swap Crypto Clipper Hides in Google Notes Extension
Unsigned software installers are distributing a dangerous new malware strain that quietly intercepts digital currency transactions. Security analysts recently uncovered the Silent Swap crypto clip…
⤷ Title: kernel.org Outage: Config Error Wipes All Linux Kernel Files
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 07:49:00 +0000
════════════════════════
⌗ Tags: #Technology #Configuration Error #kernel.org #Linux Foundation #Linux Kernel #Mirror Server #Open Source Infrastructure #outage
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 07:49:00 +0000
════════════════════════
⌗ Tags: #Technology #Configuration Error #kernel.org #Linux Foundation #Linux Kernel #Mirror Server #Open Source Infrastructure #outage
Daily CyberSecurity
kernel.org Outage: Config Error Wipes All Linux Kernel Files
Yesterday, reports emerged that kernel.org had deleted all hosted kernel files. Every archived and current kernel package became inaccessible. Affected paths returned HTTP 404 or HTTP 403 errors. …
⤷ Title: EU Court Upholds €4.1 Billion Google Android Antitrust Fine
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 07:35:07 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Android Monopoly #Big Tech Regulation #CJEU Ruling #Digital Markets Act #EU Fine #Google Antitrust
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 07:35:07 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Android Monopoly #Big Tech Regulation #CJEU Ruling #Digital Markets Act #EU Fine #Google Antitrust
Daily CyberSecurity
EU Court Upholds €4.1 Billion Google Android Antitrust Fine
After nearly a decade of legal battles, the EU’s antitrust case against Google has finally reached its end. The Court of Justice of the EU dismissed Google’s final appeal, along with A…
⤷ Title: Glitch SPY Android RAT Spreads Through a Fake Polish Rental App
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 07:30:11 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Service abuse #Android Malware #Android RAT #Brokewell #Crypto Clipper #Cyble #fake rental app #Glitch SPY
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 07:30:11 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Service abuse #Android Malware #Android RAT #Brokewell #Crypto Clipper #Cyble #fake rental app #Glitch SPY
Daily CyberSecurity
Glitch SPY Android RAT Spreads Through a Fake Polish Rental App
At a glance Malware family Glitch SPY (Android RAT and builder platform) Threat actor Unattributed; operator unidentified Targets People seeking rental properties in Poland; Polish speakers Delive…
⤷ Title: ToddyCat APT Umbrij Tool Steals Cloud Email Tokens
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 06:22:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #OAuth Theft #ToddyCat APT #Umbrij tool
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 06:22:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #OAuth Theft #ToddyCat APT #Umbrij tool
Daily CyberSecurity
ToddyCat APT Umbrij Tool Steals Cloud Email Tokens
Security analysts recently discovered the ToddyCat APT Umbrij tool. It hijacks corporate Gmail accounts without triggering standard security alerts. Attackers use this malware to execute OAuth tok…
⤷ Title: Active ColdFusion Arbitrary Code Execution Flaw Scores CVSS 10
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 04:09:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #ColdFusion #CVE_2026_48282 #Path Traversal
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 04:09:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #ColdFusion #CVE_2026_48282 #Path Traversal
Daily CyberSecurity
Active ColdFusion Arbitrary Code Execution Flaw Scores CVSS 10
TL;DR CVE-2026-48282, a critical CVSS 10 ColdFusion arbitrary code execution vulnerability, is under active attack. Hackers are exploiting this path traversal flaw in the wild. Administrators must…
⤷ Title: Public PoC Code Exposes CVSS 9.8 Control Web Panel SQL Injection CVE-2026-57517
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 03:47:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Control Web Panel #CVE_2026_57517 #sql injection #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 03:47:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Control Web Panel #CVE_2026_57517 #sql injection #Vulnerability
Daily CyberSecurity
Public PoC Code Exposes CVSS 9.8 Control Web Panel SQL Injection CVE-2026-57517
Security researchers publicly disclosed a critical vulnerability in Control Web Panel alongside proof-of-concept exploit code. This flaw, identified as CVE-2026-57517, carries a maximum CVSS score…
⤷ Title: UltraVNC Repeater Vulnerabilities Allow Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 02:20:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #buffer overflow #CVE_2026_7839 #CVE_2026_7840 #Hardcoded Password #Remote Access #UltraVNC #UltraVNC repeater
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 02:20:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #buffer overflow #CVE_2026_7839 #CVE_2026_7840 #Hardcoded Password #Remote Access #UltraVNC #UltraVNC repeater
Daily CyberSecurity
UltraVNC Repeater Vulnerabilities Allow Remote Code Execution
TL;DR Researchers disclosed two UltraVNC repeater vulnerabilities in the tool’s HTTP admin server. One allows arbitrary code execution without any login. The other exposes a hardcoded admin …
⤷ Title: WatchGuard Firebox Vulnerabilities Include Critical Unauthenticated RCE Flaw
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 02:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_13368 #Firebox #Fireware OS #Remote Code Execution #WatchGuard
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 02:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_13368 #Firebox #Fireware OS #Remote Code Execution #WatchGuard
Daily CyberSecurity
WatchGuard Firebox Vulnerabilities Include Critical Unauthenticated RCE Flaw
TL;DR WatchGuard has patched seven WatchGuard Firebox vulnerabilities in its Fireware OS. The worst, CVE-2026-13368 (CVSS 9.2), lets a remote unauthenticated attacker run code on affected applianc…
⤷ Title: Apache ActiveMQ Vulnerabilities Allow Denial of Service and Takeover
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 01:54:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ActiveMQ vulnerability #Apache ActiveMQ #CVE_2026_54475 #Denial of Service #dos #Message Broker Security #OpenWire #STOMP
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 01:54:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ActiveMQ vulnerability #Apache ActiveMQ #CVE_2026_54475 #Denial of Service #dos #Message Broker Security #OpenWire #STOMP
Daily CyberSecurity
Apache ActiveMQ Vulnerabilities Allow Denial of Service and Takeover
TL;DR Apache patched nine Apache ActiveMQ vulnerabilities in version 6.2.7. Most cause denial of service, and several need no login. One flaw lets a connection hijack another connection’s te…
⤷ Title: Icinga 2 Vulnerabilities Allow Unauthenticated Node Takeover
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 01:12:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #DSL injection #GHSA_vj39_ww8j_vvx5 #Icinga #Icinga 2 #Monitoring #network monitoring #node takeover #stack overflow
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 01:12:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #DSL injection #GHSA_vj39_ww8j_vvx5 #Icinga #Icinga 2 #Monitoring #network monitoring #node takeover #stack overflow
Daily CyberSecurity
Icinga 2 Vulnerabilities Allow Unauthenticated Node Takeover
TL;DR Icinga patched three Icinga 2 vulnerabilities on 29 June 2026. Two let an unauthenticated attacker take over or crash the monitoring server. The third affects authenticated API users only. C…
⤷ Title: StoneFly Storage Concentrator Flaws Allow Unauthenticated Root Access
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 00:55:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA ICS advisory #Command Injection #CVE_2026_55721 #CVE_2026_56413 #CVE_2026_56415 #hardcoded credentials #sql injection #Stonefly #StoneFly Storage Concentrator
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 00:55:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA ICS advisory #Command Injection #CVE_2026_55721 #CVE_2026_56413 #CVE_2026_56415 #hardcoded credentials #sql injection #Stonefly #StoneFly Storage Concentrator
Daily CyberSecurity
StoneFly Storage Concentrator Flaws Allow Unauthenticated Root Access
TL;DR CISA published an advisory for five StoneFly Storage Concentrator vulnerabilities on 30 June 2026. Two rate a maximum CVSS score of 10.0. Both let an unauthenticated attacker run commands as…
⤷ Title: Microsoft Exchange Vulnerability CVE-2026-45504 Gets Public PoC Exploit
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 00:03:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Read #CVE_2026_45504 #Exchange Server 2019 #HawkTrace #Microsoft Exchange #PoC Exploit #ssrf
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 00:03:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Read #CVE_2026_45504 #Exchange Server 2019 #HawkTrace #Microsoft Exchange #PoC Exploit #ssrf
Daily CyberSecurity
Microsoft Exchange Vulnerability CVE-2026-45504 Gets Public PoC Exploit
TL;DR Researchers at HawkTrace published full technical details and proof-of-concept code for a Microsoft Exchange vulnerability tracked as CVE-2026-45504. The flaw lets a low-privileged user read…
⤷ Title: Citrix NetScaler Vulnerability CVE-2026-8451 Exploited in the Wild as PoC Goes Public
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 17:12:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Citrix #CitrixBleed #CVE_2026_8451 #exploited in the wild #NetScaler
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 17:12:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Citrix #CitrixBleed #CVE_2026_8451 #exploited in the wild #NetScaler
Daily CyberSecurity
Citrix NetScaler Vulnerability CVE-2026-8451 Exploited in the Wild as PoC Goes Public
TL;DR Attackers are exploiting a Citrix NetScaler vulnerability in the wild, tracked as CVE-2026-8451 (CVSS 8.8). The pre-auth memory overread affects appliances configured as a SAML identity prov…
⤷ Title: It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)
════════════════════════
𐀪 Author: Sina Kheirkhah (@SinSinology)
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 16:38:28 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Sina Kheirkhah (@SinSinology)
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 16:38:28 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)
We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is just not working.
Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to…
Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to…
⤷ Title: Is the Android Lock Screen an Illusion? How I Bypassed It via the Gemini App
════════════════════════
𐀪 Author: Mustafa Salih Berk
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 10:17:04 GMT
════════════════════════
⌗ Tags: #security #bug_bounty #cybersecurity #bugbounty_writeup #vulnerability
════════════════════════
𐀪 Author: Mustafa Salih Berk
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 10:17:04 GMT
════════════════════════
⌗ Tags: #security #bug_bounty #cybersecurity #bugbounty_writeup #vulnerability
Medium
Is the Android Lock Screen an Illusion? A Critical Logical Bypass Discovered in the Gemini App
Technical analysis of a logical lock screen bypass I discovered in Google Gemini and reported via Google VRP.
⤷ Title: O mercado brasileiro de segurança em números: o que cinco anos de pesquisa revelam
════════════════════════
𐀪 Author: BugHunt
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 19:02:10 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: BugHunt
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 19:02:10 GMT
════════════════════════
⌗ Tags: No_Tags
BugHunt
O mercado brasileiro de segurança em números: o que cinco anos de pesquisa revelam
Em 2021, apenas 14% das empresas investiam em segurança há mais de cinco anos. Em 2026, esse número chegou a 67%. Cinco anos foram suficientes para que a maioria do mercado cruzasse a fronteira da maturidade operacional.
Esses dados fazem parte do Brazilian…
Esses dados fazem parte do Brazilian…
⤷ Title: Visma Case Study Part 2: Cross Tenant Account Takeover
════════════════════════
𐀪 Author: Jawad Momani
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 11:34:22 GMT
════════════════════════
⌗ Tags: #bug_bounty #pentesting #infosec #hacking #cybersecurity
════════════════════════
𐀪 Author: Jawad Momani
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 11:34:22 GMT
════════════════════════
⌗ Tags: #bug_bounty #pentesting #infosec #hacking #cybersecurity
Medium
Visma Case Study Part 2: Cross Tenant Account Takeover
In my previous disclosure, I detailed how Visma and Intigriti normalized critical data leaks. I promised I would continue to expose every…
⤷ Title: Nuclei — Automate the Boring Stuff
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 11:31:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecuirty #hacking_tools #ethical_hacking #penetration_testing
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 11:31:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecuirty #hacking_tools #ethical_hacking #penetration_testing
Medium
Nuclei — Automate the Boring Stuff
What’s up everyone! Nitin here 👋