2026-06-30
2026-06-30 13:40Z
CRIT

Don't Eat the ChocoPoCs: Trojanised PoCs Hit Researchers

Sekoia TDR and YesWeHack disclosed a sophisticated supply-chain attack targeting vulnerability researchers via trojanised PoC repositories on GitHub. Malicious Python packages (frint/skytext) deliver ChocoPoC, a fully-featured Python RAT with anti-analysis capabilities, credential harvesting, and C2 via Mapbox dead-drop infrastructure. At least 7 fake CVE PoC repos identified since late 2025, exploiting researcher urgency to test new vulnerabilities.

SRFApplicationTACTA0004TACTA0001TACTA0006TACTA0007TACTA0003TACTA0009SRFSupply Chain
92
Edit Score
2026-06-30
2026-06-30 13:19Z
CRIT

CVE-2026-8655 — Citrix Netscaler_application_delivery_controller: Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8655

Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDCitrixTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 13:19Z
CRIT

CVE-2026-8452 — Citrix Netscaler_application_delivery_controller: Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8452

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDCitrixTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 13:19Z
CRIT

CVE-2026-6556 — Fastify Fastify\/express: @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6556

@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular expressions) are left unprefixed inside prefixed plugin scopes, so middleware registered with those forms does not match the actual prefixed request path. Applications that use path-scoped middleware for authentication, authorization, rate limiting, or auditing on routes inside a prefixed CVSSv3.1 9.1 (CRITICAL)

CWECWE 285VNDFastifyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-30
2026-06-30 13:19Z
CRIT

CVE-2026-58116 — Hiyouga Llama-factory: through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58116

LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. The application passes user-supplied model path input unvalidated into AutoTokenizer.from_pretrained() and AutoModel.from_pretrained() with a hardcoded trust_remote_code=True parameter, causing the Hugging Face transformers library to fetch and execute arbitra CVSSv3.1 9.8 (CRITICAL)

CWECWE 94CWECWE 829VNDHiyougaVNDLlamaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 12:16Z
CRIT

CVE-2026-8402 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8402

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Blind SQL Injection. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.16.0.  NOTE: The vendor was contacted and it was learned that the product is not supported. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 12:16Z
HIGH

CVE-2026-41053 — Incorrect: authentication caching in the team member ship expansion of the Rancher Github authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41053

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2. CVSSv3.1 8.8 (HIGH)

CWECWE 303TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-30
2026-06-30 12:16Z
CRIT

CVE-2026-14162 — Hospital: Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14162

Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDHospitalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 11:47Z
INFO

v3.10.0

Nuclei releases·github.com

Nuclei v3.10.0 released with per-host HTTP client pooling, improved host timeout handling, and 15+ bug fixes across template validation, database connection handling, and resource management. Notable fixes include proper port preservation in network templates, MySQL allowAllFiles gating, and rejection of recursive YAML includes.

SWNucleiVNDProjectdiscoveryTYPTool
52
Edit Score
2026-06-30
2026-06-30 11:16Z
HIGH

CVE-2026-49877 — Apache Activemq: Improper Authorization vulnerability in Apache ActiveMQ.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49877

Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 285VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 11:00Z
INFO

Shipping post-quantum cryptography to Python

Trail of Bits·blog.trailofbits.com

Trail of Bits shipped post-quantum cryptography support (ML-KEM and ML-DSA per NIST standards) to pyca/cryptography v48, making NIST-standardized quantum-resistant primitives available via pip install. The implementation includes Rust bindings, cross-backend API support, and AWS-LC integration; however, protocol-level adoption remains pending as the primitives introduce significant size/performance tradeoffs (signatures and ciphertexts 1–2 orders of magnitude larger than classical equivalents).

SRFApplicationSWPyca CryptographyTYPToolTECT1040
72
Edit Score
2026-06-30
2026-06-30 10:16Z
CRIT

CVE-2026-9711 — EventON: The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9711

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter and lack of preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the dat CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDEventonTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 10:00Z
CRIT

ToddyCat: your hidden email assistant. Part 2

Kaspersky Securelist·securelist.comin the wild

Kaspersky disclosed ToddyCat APT's Umbrij tool, a .NET malware that abuses Chrome/Edge remote debugging ports to steal OAuth tokens from Gmail accounts without user interaction. The tool leverages DLL sideloading, headless browser automation via Puppeteer Sharp, and copied user profiles to bypass authentication and extract authorization codes for full email/Drive/Calendar access. The attack chain—dubbed Shadow Token via Remote Debug (STRD)—evades EDR/EPP detection by operating in headless mode and leaving no visible browser history.

TACTA0001TACTA0006SRFIdentitySRFCloudSWEdgeSWChromeVNDMicrosoftVNDGoogle
88
Edit Score
2026-06-30
2026-06-30 07:16Z
HIGH

CVE-2026-12240 — Export: The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12240

The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Successful exploitation requires an administrat CVSSv3.1 8.0 (HIGH)

CWECWE 502VNDExportTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-30
2026-06-30 06:16Z
CRIT

CVE-2026-12073 — ProfileGrid: The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12073

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly handling the error messages. This makes it possible for unauthenticated attackers to change email address of user account with ID=1 (usually an administrator), and lev CVSSv3.1 9.8 (CRITICAL)

CWECWE 639VNDProfilegridTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 02:16Z
HIGH

CVE-2026-58302 — LinuxCNC: rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58302

rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root. CVSSv3.1 8.4 (HIGH)

CWECWE 22VNDLinuxcncTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-29
2026-06-29 23:16Z
HIGH

CVE-2026-7656 — IPv6: The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7656

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 validity checks with the ICMPv6 code check using the wrong operator precedence: the form was '((length/hop/source/target checks) && (icmp_hdr-code != 0))'. Because every legitimate ND message carries ICMPv6 code 0, an attacker setting code == 0 (the normal value) caused the entire predicate to eval CVSSv3.1 8.1 (HIGH)

CWECWE 290CWECWE 670VNDIpv6TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-29
2026-06-29 21:16Z
CRIT

CVE-2026-55276 — Apache Tomcat: Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55276

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1 CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 670VNDApacheVNDAlwaysTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-29
2026-06-29 21:16Z
CRIT

CVE-2026-53434 — Apache Tomcat: Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53434

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 390VNDApacheVNDDetectionTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-29
2026-06-29 21:16Z
HIGH

CVE-2026-34597 — Coolify: Prior to 4.0.0-beta.470, a critical Authenticated Host Remote Code Execution (RCE) vulnerability was discovered

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34597

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.470, a critical Authenticated Host Remote Code Execution (RCE) vulnerability was discovered in Coolify. The flaw resides in the handling of user-defined build parameters for the Nixpacks build pack. Specifically, the install_command provided by a user is directly concatenated into a shell command string that is executed on the deployment host during the buil CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 21:16Z
HIGH

CVE-2026-34594 — Coolify: Prior to 4.0.0-beta.471, an authenticated command injection vulnerability in the Destination Network Management functionality

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34594

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command injection vulnerability in the Destination Network Management functionality allows users with destination management permissions to execute arbitrary commands as root on managed servers. The "network" parameter is passed directly to shell commands without proper sanitization, enabling full remote code execution on the host syste CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDCoolifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 21:03Z
CRIT

Accelerating EDR Evasion with LLM-Driven Analysis

SpecterOps·specterops.io

SpecterOps demonstrates automated LLM-driven reverse engineering of Palo Alto Cortex XDR to extract and decrypt detection rules, behavioral models, and YARA signatures. The research details a "Day Shift" harness using GPT-5.5-Cyber with Binary Ninja to systematically disassemble EDR protections, recover 9,350+ DSE rules and 4,209 BIOC rules in plaintext, decrypt embedded ML models, and generate actionable evasion techniques including registry export bypasses and process spoofing.

SRFApplicationSRFOsTACTA0005OSWindowsSWCortex XdrVNDPaloaltoTYPResearchSTGDefense Evasion
92
Edit Score
2026-06-29
2026-06-29 20:17Z
CRIT

CVE-2026-57498 — Coolify: Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57498

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI components accept server_id and destination_uuid from URL query parameters without any team ownership validation, allowing cross-team resource deployment. This vulnerability is fixed in 4.0.0-beta.474 CVSSv3.1 9.6 (CRITICAL)

CWECWE 862CWECWE 639VNDCoolifyTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-29
2026-06-29 20:17Z
HIGH

CVE-2026-43735 — Apple Safari: The issue was addressed with improved checks.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43735

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin. CVSSv3.1 8.1 (HIGH) · EPSS 18th percentile

CWECWE 352VNDAppleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-29
2026-06-29 20:17Z
HIGH

CVE-2026-43731 — A use-after-free issue was addressed with improved memory management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43731

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to memory corruption. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score