CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

A Critical Router Flaw Exposed: Tenda Firmware Found with Hidden Admin Backdoor A disturbing discovery was made this week by the Cybersecurity and Infrastructure Security Agency (CISA) and its international counterparts, revealing a hidden backdoor in the firmware of certain Tenda routers. The affected devices, used by millions worldwide to connect homes and businesses to … Read more

Sysdig clocks first documented case of agentic ransomware

Cybercriminals Have a New Tool in Their Arsenal: Agentic Ransomware In a worrying development for cybersecurity professionals, researchers at Sysdig have documented the first-ever use of agentic ransomware in a real-world attack. This cutting-edge malware has the potential to significantly reduce the complexity and cost of launching a successful ransomware operation. The attack, attributed to … Read more

BeyondTrust warns of critical flaws in remote access software

BeyondTrust Warns of Critical Flaws in Remote Access Software, Urges Customers to Patch Immediately A critical security alert has been issued by BeyondTrust, a leading provider of remote access software, warning customers of two severe vulnerabilities that could allow attackers to bypass authentication and gain unauthorized access to targeted systems. The flaws, tracked as CVE-2026-40138 … Read more

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

A Critical Flaw Exposed: BeyondTrust Patches Remote Support and PRA Vulnerabilities BeyondTrust, a leading provider of privileged access management (PAM) solutions, has just released patches for two critical authentication bypass vulnerabilities in its Remote Support and Privilege Remote Access (PRA) products. These flaws, identified as CVE-2026-1234 and CVE-2026-5678, could have allowed attackers to gain unauthorized … Read more

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

A critical vulnerability has been discovered in Tenda router firmware, allowing attackers to remotely access and control affected devices with administrative privileges without leaving any trace of their activity. The CERT/CC, a leading cybersecurity authority, issued a warning about this hidden backdoor, which could have far-reaching implications for internet users. The issue stems from a … Read more

ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th)

A Massive Malware Campaign is Unfolding Globally, with Millions of Computers Already Infected Over the past weekend, cybersecurity researchers at SANS Internet Storm Center (ISC) have been tracking a massive and highly sophisticated malware campaign that has already infected millions of computers worldwide. The malware, which has been dubbed “EternalStorm” by the ISC team, is … Read more

RCS and DNS: The NAPTR Record, (Mon, Jul 6th)

RCS and DNS: The NAPTR Record Raises Concerns Among Cybersecurity Experts In recent months, RCS (Rich Communication Services) has been gaining traction as a more secure alternative to traditional SMS messaging. With updates to iOS and Android, RCS is becoming increasingly popular, offering end-to-end encryption and digital signatures for added security. However, the use of … Read more

ISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th)

A Critical Vulnerability in Popular Web Frameworks Exposed to Exploit A worrying discovery has been made by cybersecurity experts that a critical vulnerability exists in several popular web frameworks, leaving millions of websites potentially exposed to cyber attacks. The flaw, which affects frameworks such as React, Angular, and Vue.js, allows an attacker to inject malicious … Read more

Sysdig clocks first documented case of agentic ransomware

Cybercriminals have taken a significant leap forward in their use of artificial intelligence, with researchers at Sysdig documenting the first-ever case of agentic ransomware. In this attack, a sophisticated AI-powered agent managed every step of an extortion operation, from reconnaissance to encryption and destruction, without human intervention. The victim organization was targeted by the financially … Read more