HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 16, 2026.
-
The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
— Unit 42
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The… -
Dutch police bust investment fraud ring stealing over €100 million
— Bleeping Computer
The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated … -
Forgotten Bootloaders Expose Secure Boot Blind Spot
— Dark Reading
Nearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot. -
Identity Attacks Overtake Exploits as Top Ransomware Cause
— Dark Reading
Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credenti… -
Zoom warns of critical account takeover vulnerability
— Bleeping Computer
Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an una… -
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
— The Hacker News
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolu… -
Google Gemini CLI abused as a hacking agent, malware botnet operator
— Bleeping Computer
A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small… -
Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
— Dark Reading
We're thrilled to unveil the latest evolution of Dark Reading's DR Global section — your go-to source for region-specific cybersecurity in… -
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
— The Hacker News
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wal… -
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
— The Hacker News
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerab… -
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
— Unit 42
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. Th… -
ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (8316 in last 30 days).
Critical: 4 · High: 6 · Medium: 9 · Low: 1. View full dashboard →
-
CVE-2026-15907
— CVSS 7.3 (HIGH)
A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of the argument subject can lead to sql injection⦠-
CVE-2026-62314
— CVSS 5.8 (MEDIUM)
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go PathChecker.Check() trusted the client⦠-
CVE-2026-55652
— CVSS 9.8 (CRITICAL)
Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the⦠-
CVE-2026-55234
— CVSS 8.5 (HIGH)
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored sou⦠-
CVE-2026-54458
— CVSS 9.6 (CRITICAL)
WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript i⦠-
CVE-2026-53447
— CVSS 6.5 (MEDIUM)
Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking ⦠-
CVE-2026-52892
— CVSS 6.5 (MEDIUM)
Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of write-level Authentication.checkBoardWriteAcces⦠-
CVE-2026-52891
— CVSS 9.9 (CRITICAL)
Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avata⦠-
CVE-2026-52890
— CVSS 7.1 (HIGH)
Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled versions.original.p⦠-
CVE-2026-50183
— CVSS 4.7 (MEDIUM)
WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the snippet.title field returned by the YouTube Data ⦠-
CVE-2026-50182
— CVSS 6.1 (MEDIUM)
WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. The $_GET['search'] query parameter is concatenate⦠-
CVE-2026-48795
— CVSS 8.6 (HIGH)
AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted a⦠-
CVE-2026-45313
— CVSS 7.7 (HIGH)
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a⦠-
CVE-2026-15921
— CVSS 3.1 (LOW)
Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that refresh remote LTS aliases, such as `nvm ⦠-
CVE-2026-62361
— CVSS 5.5 (MEDIUM)
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscribers/export endpoint injects the user-controlled query parameter into QuerySubscribersForExport in ⦠-
CVE-2026-62312
— CVSS 8.8 (HIGH)
9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host operating system by combining a Host header bypass of localhost-only r⦠-
CVE-2026-56678
— CVSS 6.4 (MEDIUM)
9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled region value, allowing an authenticated attacker to ⦠-
CVE-2026-55608
— CVSS 4.2 (MEDIUM)
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true could allow an authenticated tenant⦠-
CVE-2026-55410
— CVSS 6.7 (MEDIUM)
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the databas⦠-
CVE-2026-54052
— CVSS 9.9 (CRITICAL)
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's locaâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · July 16, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com