we_are_coded.by CODE · The world, decoded
БГ
we are coded

Security, p. 8

Security

68 stories · page 8 of 8
Security
CISA2 July 2026

A critical hole in SimpleHelp lets an attacker in without a password - and it's already being used in attacks

CVE-2026-48558 bypasses the OIDC token check in SimpleHelp, a remote support tool. Arctic Wolf is seeing active exploitation with a credential stealer. CISA gave federal agencies until 2 July.

Read →
Security
Cato Networks1 July 2026

Researchers showed how Cursor's AI agent could execute code on your machine with one hidden prompt

CVE-2026-50548 and CVE-2026-50549, both CVSS 9.8: a hidden instruction in one resource was enough to make Cursor's agent write outside its sandbox and execute commands. Patched in Cursor 3.0. No data on real attacks so far.

Read →
Security
CISA29 June 2026

Actively exploited holes - and in home equipment

CISA added new vulnerabilities with proven active exploitation - among them in Ubiquiti UniFi and SimpleHelp. This isn't theory. Someone is already using them. The patch doesn't wait.

Read →
Security
Microsoft Security18 May 2026

One stolen identity, one whole cloud breached

Microsoft disclosed Storm-2949: the attacker takes over a single user through social engineering targeting a password reset and MFA. Then the attacker drains keys, files, and databases from the entire cloud.

Read →
Security
Cloudflare3 March 2026

Attacks no longer break down the door - they walk in with your key

Cloudflare reported a record DDoS attack of 31.4 Tbps for 2026. But the real change is elsewhere - 94% of login attempts come from bots, and 63% of those carry passwords already stolen.

Read →