CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

A critical vulnerability has been discovered in Tenda router firmware, allowing attackers to remotely access and control affected devices with administrative privileges without leaving any trace of their activity. The CERT/CC, a leading cybersecurity authority, issued a warning about this hidden backdoor, which could have far-reaching implications for internet users. The issue stems from a … Read more

ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th)

A Massive Malware Campaign is Unfolding Globally, with Millions of Computers Already Infected Over the past weekend, cybersecurity researchers at SANS Internet Storm Center (ISC) have been tracking a massive and highly sophisticated malware campaign that has already infected millions of computers worldwide. The malware, which has been dubbed “EternalStorm” by the ISC team, is … Read more

RCS and DNS: The NAPTR Record, (Mon, Jul 6th)

RCS and DNS: The NAPTR Record Raises Concerns Among Cybersecurity Experts In recent months, RCS (Rich Communication Services) has been gaining traction as a more secure alternative to traditional SMS messaging. With updates to iOS and Android, RCS is becoming increasingly popular, offering end-to-end encryption and digital signatures for added security. However, the use of … Read more

ISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th)

A Critical Vulnerability in Popular Web Frameworks Exposed to Exploit A worrying discovery has been made by cybersecurity experts that a critical vulnerability exists in several popular web frameworks, leaving millions of websites potentially exposed to cyber attacks. The flaw, which affects frameworks such as React, Angular, and Vue.js, allows an attacker to inject malicious … Read more

Sysdig clocks first documented case of agentic ransomware

Cybercriminals have taken a significant leap forward in their use of artificial intelligence, with researchers at Sysdig documenting the first-ever case of agentic ransomware. In this attack, a sophisticated AI-powered agent managed every step of an extortion operation, from reconnaissance to encryption and destruction, without human intervention. The victim organization was targeted by the financially … Read more

US Army websites defaced with pro-Kurdish sentiments, insults to Trump

US Army Websites Defaced with Pro-Kurdish Sentiments and Insults to Trump Multiple US Army internet subdomains have been defaced in a sophisticated cyber attack, displaying pro-Kurdish sentiments and insulting messages towards President Donald Trump and United States Ambassador to Türkiye Tom Barrack. The incident highlights the vulnerability of military websites to cyber threats and raises … Read more

US Army websites defaced with pro-Kurdish sentiments, insults to Trump

US Army Websites Defaced with Pro-Kurdish Sentiments and Insults to Trump The US Army’s online presence has been compromised in a brazen display of cyber vandalism, as multiple subdomains were defaced with pro-Kurdish sentiments and insults directed at President Donald Trump. The incident, which was first reported by independent cybersecurity researcher Ronald Lovelace, highlights the … Read more

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability

A newly disclosed Linux vulnerability, dubbed “Bad Epoll,” has made its way into the public sphere with a proof-of-concept (PoC) exploit that could grant unprivileged processes root access on desktops, servers, and even Android phones. The bug, assigned a CVSS score of 7.8 and tracked as CVE-2026-46242, exploits a race-condition use-after-free issue in the Linux … Read more

North Korean Hackers Target Open Source Developers in Supply Chain Attacks

North Korean Hackers Launch Widespread Supply Chain Attacks on Open Source Developers A sophisticated campaign by North Korean hackers has been targeting open source software developers across various platforms, compromising their repositories and injecting malicious code into legitimate packages. The operation, referred to as PolinRider, is part of a broader supply chain attack that has … Read more

Armored Likho APT Targeting Government, Electric Power Entities

A Sophisticated Threat Actor Targets Government and Electric Power Organizations Worldwide A highly skilled threat actor, dubbed Armored Likho, has been identified as targeting government and electric power organizations in multiple countries. According to Kaspersky, this advanced persistent threat (APT) group engages in financially motivated attacks against individuals and cyber-espionage operations against organizations in Russia, … Read more