Daily News
AsyncAPI npm Supply Chain Attack: No Token Stolen
The AsyncAPI npm supply chain attack shows that neither of the two controls teams were told to trust — cryptographic provenance and blocking install scripts — actually stopped it: an attacker published four trojanized packages with valid SLSA/OIDC provenance attestations, without ever stealing an npm token, and the payload runs regardless of –ignore-scripts. What Happened…
Read MoreOracle E-Business Suite CVE-2026-46817 Actively Exploited
Oracle E-Business Suite CVE-2026-46817, a critical flaw, is under active exploitation: an unauthenticated attacker with nothing more than HTTP access can take over Oracle Payments — the module that executes your payment runs. CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 15 and gave US federal agencies three days to fix…
Read MoreSonicWall SMA1000 CVE-2026-15409 RCE: Patch by July 17
SonicWall confirmed that the SonicWall SMA1000 CVE-2026-15409 RCE chain is being actively exploited: an unauthenticated attacker can force a target appliance into arbitrary requests, then pivot to full administrator-level command execution — no valid login required at any point. CISA added both flaws to its Known Exploited Vulnerabilities catalog, with a federal remediation deadline of…
Read MoreGodDamn Ransomware PoisonX Driver Kills EDR
The GodDamn ransomware PoisonX driver is a Microsoft-signed kernel tool that ransomware operators use to silently kill EDR and antivirus processes before deploying encryption — and because the driver carries a legitimate Microsoft signature, standard driver-trust checks wave it straight through. What Happened Symantec disclosed on July 9, 2026 that a ransomware family called GodDamn…
Read MoreMicrosoft July 2026 Patch Tuesday Zero-Day Hits SharePoint
The Microsoft July 2026 Patch Tuesday zero-day count is the largest disclosure on record — trackers put the total at 570 to 622 CVEs depending on methodology — and two of the fixed flaws were already being exploited before the patch shipped: one in Active Directory Federation Services, one in SharePoint Server. A separate, publicly…
Read More
