Posts by Editorial Team
AsyncAPI npm Supply Chain Attack: No Token Stolen
The AsyncAPI npm supply chain attack shows that neither of the two controls teams were told to trust — cryptographic provenance and blocking install scripts — actually stopped it: an attacker published four trojanized packages with valid SLSA/OIDC provenance attestations, without ever stealing an npm token, and the payload runs regardless of –ignore-scripts. What Happened…
Read MoreOracle E-Business Suite CVE-2026-46817 Actively Exploited
Oracle E-Business Suite CVE-2026-46817, a critical flaw, is under active exploitation: an unauthenticated attacker with nothing more than HTTP access can take over Oracle Payments — the module that executes your payment runs. CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 15 and gave US federal agencies three days to fix…
Read MoreSonicWall SMA1000 CVE-2026-15409 RCE: Patch by July 17
SonicWall confirmed that the SonicWall SMA1000 CVE-2026-15409 RCE chain is being actively exploited: an unauthenticated attacker can force a target appliance into arbitrary requests, then pivot to full administrator-level command execution — no valid login required at any point. CISA added both flaws to its Known Exploited Vulnerabilities catalog, with a federal remediation deadline of…
Read MoreTop 5 Cybersecurity News Stories July 17, 2026
The five stories in this week’s Cybersecurity News Stories July 17, 2026 share a structural property that distinguishes them from the opportunistic exploitation patterns that characterised earlier months of this year: in each case, the compromised or exposed component is one the organisation has placed into a category other than “security risk.” A remote-access appliance…
Read MoreGodDamn Ransomware PoisonX Driver Kills EDR
The GodDamn ransomware PoisonX driver is a Microsoft-signed kernel tool that ransomware operators use to silently kill EDR and antivirus processes before deploying encryption — and because the driver carries a legitimate Microsoft signature, standard driver-trust checks wave it straight through. What Happened Symantec disclosed on July 9, 2026 that a ransomware family called GodDamn…
Read More
