CVE-2026-26220: Critical LightLLM Flaw Enables Unauthenticated Remote Code Execution via Unsafe Pickle Deserialization
LightLLM — Unauthenticated Remote Code Execution via pickle.loads() CVE ID: CVE-2026-26220Product: LightLLMAffected Component: PD (Prefill-Decode) Disaggregation Mode…
continue reading..
CVE-2026-22208: Critical OpenS100 Lua Flaw Enables Remote Code Execution Through Malicious Chart Files
OpenS100 – Unrestricted Lua Execution Leading to Remote Code Execution CVE ID: CVE-2026-22208Product: OpenS100 (S-100 Portrayal Engine)Vulnerability…
continue reading..
CVE-2025-66614: Apache Tomcat mTLS Bypass Lets Attackers Slip Past Client Certificate Authentication via SNI Mismatch
Apache Tomcat — SNI-Based Client Certificate Authentication Bypass CVE ID: CVE-2025-66614Vendor: ApacheProduct: Apache TomcatVulnerability Type: Authentication BypassCWE:…
continue reading..
CVE-2026-22769: Critical Hardcoded Credential in Dell RecoverPoint Enables Remote Root Takeover
Dell RecoverPoint for Virtual Machines – Hardcoded Credential Leading to Remote Root Access CVE ID: CVE-2026-22769Affected Product:…
continue reading..
CRESCENTHARVEST Cyberespionage Campaign Targets Iranian Protestors with Stealthy Malware and DLL Sideloading Techniques
In early 2026, researchers from the Acronis Threat Research Unit (TRU) identified a sophisticated cyberespionage campaign —…
continue reading..
Supply Chain Subversion: How SmartLoader Leveraged a Trojanized Oura MCP Server to Deploy StealC
The ongoing evolution of malware distribution tactics has taken another significant turn with the discovery of a…
continue reading..
Cybercriminals Exploit ScreenConnect in SmartScreen Bypass Campaign to Gain Stealth Remote Access
1. Introduction: Threat Overview ConnectWise ScreenConnect (ConnectWise Control) is a remote support and Remote Monitoring & Management…
continue reading..
Researchers Warn: “Zero-Knowledge” Password Managers May Not Be as Secure as Claimed
Cloud-based password managers have become fundamental tools in modern digital life, helping users store and retrieve hundreds…
continue reading..
Firmware-Level Android Backdoor “Keenadu” Discovered, Exposing Supply Chain Compromise in Pre-Installed Devices
In early 2026, researchers at Kaspersky’s Global Research & Analysis Team (GReAT) uncovered a sophisticated Android backdoor,…
continue reading..
