Security, p. 7
Security
68 stories · page 7 of 8Four Joomla extensions land on the actively exploited list in four days
CISA added Balbooa Forms and iCagenda to its catalog of vulnerabilities being exploited right now. Both allow unauthenticated file upload and code execution on the server. Three days earlier, two other Joomla extensions joined the same list - with the same hole.
Read →Ten holes in curl: your passwords can travel to a stranger's server on a redirect
Ubuntu patched ten holes in curl at once - the tool that fetches something in every script, container and CI pipeline. The ugliest one sends saved passwords to a server that simply returned a redirect. Advisory-level note: it doesn't claim active exploitation.
Read →Ubuntu patched a pile of holes in Apache - the kind of fix nobody notices until it's too late
Ubuntu tightened up Apache with one patch that closes 12 holes at once. All three supported LTS versions are affected. There's one action: you update.
Read →A vulnerability in Adobe ColdFusion scored 10.0 is being actively exploited
CISA added CVE-2026-48282 to the Known Exploited Vulnerabilities catalog over evidence of active exploitation. NVD scores it 10.0 on CVSS - the maximum value. Federal agencies have until 10 July.
Read →Seven holes in FatFs threaten millions of embedded devices, and there's no full patch
runZero disclosed 7 vulnerabilities at once in the FatFs file system - embedded in drones, cameras, hardware wallets, and dozens of platforms. Only one has been patched. For the rest, there's no fix yet.
Read →A hole in the heart of Linux hands root to anyone, and AI had walked right past it
CVE-2026-46242. Use-after-free in epoll that escalates an ordinary user to root - on desktops, servers, even Android. The irony: Anthropic's AI model Mythos found the neighboring bug in the same code. This exact one, it missed.
Read →FBI and Google pulled the plug on 2 million hijacked home devices
On 2 July the FBI seized the domains of NetNut. Google tore down the backend. The network - one of the largest residential proxies - was secretly turning smart TVs and routers into cover for cybercriminals and spies.
Read →Insurer discloses breach, data on millions of customers leaked
Insurance giant Aflac disclosed a breach through its Japanese subsidiary. According to the company, personal and financial data of millions of customers leaked. The US systems were not affected.
Read →A SharePoint hole is being actively exploited, and Microsoft had underrated it
Attackers are already using a hole in on-premises SharePoint (Microsoft's document software) - in real attacks, not in theory. CISA added it to the list of actively exploited vulnerabilities and set a patching deadline. Microsoft had rated it as unlikely to be attacked.
Read →