Collected: 2026-07-08T04:00:49.771611
No items scoring >=10 in this run.
| CVE | Vendor / Product | Score | Required Action |
|---|---|---|---|
| CVE-2026-48908 | [CISA KEV] CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability - JoomShaper SP Page Builder | 6 | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability - JoomShaper SP Page Builder. Required action: Apply mitigations in accordance with vendor instructions, ensuri |
| CVE-2026-55255 | [CISA KEV] CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability - Langflow Langflow | 6 | Langflow Authorization Bypass Through User-Controlled Key Vulnerability - Langflow Langflow. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s |
| CVE-2026-56290 | [CISA KEV] CVE-2026-56290: Joomlack Page Builder Improper Access Control Vulnerability - Joomlack Page Builder | 6 | Joomlack Page Builder Improper Access Control Vulnerability - Joomlack Page Builder. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-0 |
| CVE-2026-48282 | [CISA KEV] CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability - Adobe ColdFusion | 6 | Adobe ColdFusion Path Traversal Vulnerability - Adobe ColdFusion. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Secu |
thegentlemen: LogiQuip, Victim: LogiQuip | Group: thegentlemen | Website: , Mercado Libre, Victim: Mercado Libre | Group: thegentlemen | Webs, Shamrock Holdings Inc., Victim: Shamrock Holdings Inc. | Group: thegentlem, Medic Rescue, Victim: Medic Rescue | Group: thegentlemen | Websi, Virginia Historical Society, Victim: Virginia Historical Society | Group: thege, Quanterm Logistics Sdn Bhd, Victim: Quanterm Logistics Sdn Bhd | Group: thegen, Spedidam, Victim: Spedidam | Group: thegentlemen | Website: , hiddeenn, Victim: hiddeenn | Group: thegentlemen | Details: , Arabia Falcon Insurance Company SAOG, Victim: Arabia Falcon Insurance Company SAOG | Gro, Ce Ratp Comite D entreprise Ratp, Victim: Ce Ratp Comite D entreprise Ratp | Group: , Keifert, Victim: Keifert | Group: thegentlemen | Website: k, Kosmos, Victim: Kosmos | Group: thegentlemen | Website: ko, EBNY Development, Victim: EBNY Development | Group: thegentlemen | W, Tonnies Group, Victim: Tonnies Group | Group: thegentlemen | Webs, Automovil Supply S.A, Victim: Automovil Supply S.A | Group: thegentlemen, Excel Cell Electronic, Victim: Excel Cell Electronic | Group: thegentleme, CSIR Structural Engineering Research Centre, Victim: CSIR Structural Engineering Research Centr, Jump Solutions Inc, Victim: Jump Solutions Inc | Group: thegentlemen |, MBT Energy, Victim: MBT Energy | Group: thegentlemen | Website, Pro-Tech Technology, Victim: Pro-Tech Technology | Group: thegentlemen , Technical Solutions Group, Victim: Technical Solutions Group | Group: thegent
dragonforce: hive360.com, Victim: hive360.com | Group: dragonforce | Website, amplesurveyor.com, Victim: amplesurveyor.com | Group: dragonforce | W
medusalocker: Forces, Victim: Forces | Group: medusalocker | Website: fo
incransom: Aesthetic Surgical Images, Victim: Aesthetic Surgical Images | Group: incrans
qilin: Lechner Massivhaus GmbH, Victim: Lechner Massivhaus GmbH | Group: qilin | W, COP® Vertriebs-GmbH Zentrale, Victim: COP® Vertriebs-GmbH Zentrale | Group: qili, Next Clinics, Victim: Next Clinics | Group: qilin | Website: www, Accelirate, Victim: Accelirate | Group: qilin | Website: www.a
payoutsking: Welldyne, Victim: Welldyne | Group: payoutsking | Website: w, C****p, Victim: C****p | Group: payoutsking | Website: c**
play: Preneed Funeral Programs, Victim: Preneed Funeral Programs | Group: play | W, Kevin Bao Lenguyen, Victim: Kevin Bao Lenguyen | Group: play | Website, United Infrastructure, Victim: United Infrastructure | Group: play | Webs
interlock: YMCA of Western North Carolina, Victim: YMCA of Western North Carolina | Group: in
Booba Project: URA Group, Victim: URA Group | Group: Booba Project | Website
krybit: seprec.gob.bo, Victim: seprec.gob.bo | Group: krybit | Website: s
akira: RISE Architecture, Victim: RISE Architecture | Group: akira | Details, Chisholm Persson & Ball, Victim: Chisholm Persson & Ball | Group: akira | D, Excalibur Rentals, Victim: Excalibur Rentals | Group: akira | Details, Edge Solutions | Stone Ridge Payments, Victim: Edge Solutions | Stone Ridge Payments | Gr
cmdorganization: Mount Royal University, Victim: Mount Royal University | Group: cmdorganiz
bravox: PB Fiduciaire SA, Victim: PB Fiduciaire SA | Group: bravox | Website
AiLock: Studio Sardano, Victim: Studio Sardano | Group: AiLock | Website: , Richmont Graduate University, Victim: Richmont Graduate University | Group: AiLo
[8] What Changes When Your Software Supply Chain Includes AI Writing Your Code? (TheHackerNews)
Software supply chain security was hard enough. Then AI joined the build pipeline.
For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, which transitive depen
[8] Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities (TheHackerNews)
A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign.
The activity involves t
[8] CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware (TheHackerNews)
Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interfaces, the CERT Coord
[8] BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA (TheHackerNews)
BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susc
[6] Accenture confirms breach after hacker offers stolen data for sale (BleepingComputer)
IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [...]
[5] Chinese hackers develop LONGLEASH malware to expand ORB network (BleepingComputer)
Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]
[5] Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots (TheHackerNews)
A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project.
From there, they could read live conversatio
[5] Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants (TheHackerNews)
Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise.
The one-cli
Total new items: 87
Critical items: 0
Ransomware groups active: 14
Top CVEs to patch: CVE-2026-48908, CVE-2026-55255, CVE-2026-56290, CVE-2026-48282
Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live