Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Phishing was the primary means of gaining initial access this...
Cisco Talos IR reports phishing and authentication abuse as top attack vectors in Q2 2026. Ransomware incidents remained steady, with attackers using trojanized remote management tools for stealthy access.
JetBrains patched CVE-2026-63077 (CVSS 9.8) in TeamCity On-Premises, an unauthenticated remote code execution vulnerability exploitable via the agent polling protocol. All on-premises versions are affected, with fixes in versions 2025.11.7 and 2026.1.3.
JetBrains has issued an urgent warning to users of on-premise versions of TeamCity to update their software following the discovery of a critical vulnerability, CVE-2026-63077, with a CVSS score of 9.8. This flaw, discovered by Antoni Tremblay on July 10, 2026, allows unauthenticated attackers to bypass authentication checks and execute arbitrary operating system commands on the TeamCity server.
STAR Labs published a Linux kernel exploit for CVE-2026-53264 (CVSS 7.8), a use-after-free race condition in the network traffic-control subsystem that allows local privilege escalation to root on CentOS Stream 9. Researcher Lee Jia Jie used AI to discover the bug and accelerate exploit development.
STAR Labs has disclosed a Linux kernel vulnerability, CVE-2026-53264 (CVSS score: 7.8), which allows local privilege escalation to root on CentOS Stream 9. The flaw resides in the kernel’s traffic-control subsystem and involves a use-after-free race condition.