Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

A Critical NGINX Flaw Can Bring Down Servers and Potentially Allow Hackers to Run Malicious Code Remotely, Putting Millions of Websites at Risk Millions of websites worldwide are vulnerable to a critical flaw in the widely-used web server software NGINX. This bug can cause servers to crash, disrupting online services and potentially allowing hackers to … Read more

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

A Critical NGINX Vulnerability Has Been Uncovered, Potentially Leaving Thousands of Websites Vulnerable to Crash and Remote Code Execution A recently discovered vulnerability in the popular web server software NGINX has left thousands of websites potentially exposed to a devastating cyberattack. The flaw, which has been confirmed by NGINX’s developers, can cause affected servers to … Read more

Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)

Hikvision Cameras Exposed by Recon Scans Targeting Intelligent Security API A growing number of Hikvision cameras are being targeted by malicious scans designed to exploit their Intelligent Security API (ISAPI). The ISAPI is a feature-rich interface that allows third-party developers to integrate with Hikvision devices, but its potential security vulnerabilities have left these cameras exposed. … Read more

Hackers abuse ViPNet software to target Russian govt agencies

A sophisticated threat actor has been exploiting a vulnerability in the update mechanism of ViPNet software to target government agencies and other organizations in Russia. Dubbed HelloNet, this campaign has been active since at least May and has already had a significant impact on various sectors, including government, energy, transport, education, and logistics. ViPNet is … Read more

Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)

Hikvision Cameras Exposed by Recon Scans for New API Feature Hikvision cameras have long been a target for hackers due to their vulnerabilities and exposure to internet-wide scans. Now, a new threat has emerged in the form of reconnaissance scans targeting the company’s Intelligent Security API (ISAPI), which was introduced several years ago but has … Read more

Hackers abuse ViPNet software to target Russian govt agencies

A sophisticated threat actor has been exploiting the update mechanism of ViPNet software to target Russian government agencies and organizations across various sectors. The campaign, dubbed HelloNet, has been active since at least May 2026 and uses a malicious payload that acts as a proxy and loader for additional malware. ViPNet is a suite of … Read more

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

Cybersecurity firm SonicWall’s Secure Mobile Access (SMA) platform suffered a devastating blow this week, with hackers exploiting two previously unknown vulnerabilities before they were even publicly disclosed. The attack allowed unauthorized access to sensitive systems, highlighting the urgent need for swift patching and robust security measures. The affected vulnerability, a zero-day exploit in SMA version … Read more

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Ukrainian Devices Infected with Malware via ClickFix CAPTCHAs In a disturbing example of the dark side of artificial intelligence, Ukrainian users have been targeted by a sophisticated malware campaign that exploits ClickFix CAPTCHAs. These seemingly innocuous images are actually being used to deliver malicious payloads, leaving thousands of devices compromised. The malware in question is … Read more

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A pair of zero-day vulnerabilities in SonicWall’s SMA (Secure Mobile Access) platform were exploited by attackers before a patch was made available, granting them root access and compromising sensitive data. The exploitation occurred despite the company’s claims that no customers had been affected prior to disclosure. SonicWall’s SMA is a popular solution for remote access … Read more

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

A New Malware Threat Emerges, Targeting Ukrainian Devices with Sophisticated CAPTCHA-based Attacks Cybersecurity researchers have uncovered a sophisticated malware attack targeting devices in Ukraine, leveraging a unique approach that exploits the ClickFix CAPTCHA system. This threat highlights the evolving nature of cyberattacks and underscores the importance of vigilance in protecting against emerging vulnerabilities. The UAC-0145 … Read more