Skip to the content
logo main
  • News
  • How To
  • Members Area
  • About me
  • English
    • Italiano
    • Français
    • Deutsch
    • English
logo main
A wave of product vulnerabilities hits security vendors and enterprise software
18/07/2026
News
by Giuseppe

A wave of product vulnerabilities hits security vendors and enterprise software

Numerous vendors disclosed severe flaws across the security and enterprise software stack, including Zoom, FortiSandbox, FreeRDP, NGINX, SAP, Adobe, Siemens, Schneider Electric, an

Read more
Google and Microsoft are tightening identity and OAuth telemetry after stealthy account attacks
18/07/2026
News
by Giuseppe

Google and Microsoft are tightening identity and OAuth telemetry after stealthy account attacks

Attackers have started abusing OAuth client ID behavior in Microsoft Entra ID to enumerate accounts and evade normal sign-in logging. Proofpoint showed that spoofed client IDs can

Read more
RedHook, LabubaRAT, and other mobile malware families widen Android abuse
18/07/2026
News
by Giuseppe

RedHook, LabubaRAT, and other mobile malware families widen Android abuse

Several mobile malware reports this week showed attackers expanding their Android tradecraft. RedHook was observed using Wireless ADB to gain shell access without a computer connec

Read more
U-Boot and old Secure Boot shims expose a long-lived firmware trust problem
18/07/2026
News
by Giuseppe

U-Boot and old Secure Boot shims expose a long-lived firmware trust problem

Researchers disclosed six vulnerabilities in U-Boot and separately showed that 11 Microsoft-signed UEFI shim bootloaders can still undermine Secure Boot. These boot-chain problems

Read more
Lidl and EY both disclosed third-party support and service-provider data breaches
18/07/2026
News
by Giuseppe

Lidl and EY both disclosed third-party support and service-provider data breaches

Lidl notified customers in Germany, Belgium, and the Netherlands that a breach at an external IT service provider exposed customer data stored in a separate file. The retailer said

Read more
Google and Microsoft move decisively toward passkeys and stronger sign-in defaults
18/07/2026
News
by Giuseppe

Google and Microsoft move decisively toward passkeys and stronger sign-in defaults

Microsoft announced major changes to Entra ID that make passkeys the default authentication experience in the public cloud, with SMS and voice gradually being phased down. The comp

Read more
A rash of CMS and Joomla flaws is being actively exploited for webshell and file-upload attacks
18/07/2026
News
by Giuseppe

A rash of CMS and Joomla flaws is being actively exploited for webshell and file-upload attacks

Australia's Signals Directorate warned that attackers are mounting a broad campaign against content management systems, including WordPress and Joomla, by exploiting known fla

Read more
CISA pushes vendors toward more disciplined coordinated vulnerability disclosure
18/07/2026
News
by Giuseppe

CISA pushes vendors toward more disciplined coordinated vulnerability disclosure

CISA and allied agencies published new coordinated vulnerability disclosure guidance aimed at helping vendors handle reports more consistently. The guidance arrived shortly after C

Read more
ClickFix becomes a scalable social-engineering platform for malware delivery
18/07/2026
News
by Giuseppe

ClickFix becomes a scalable social-engineering platform for malware delivery

ClickFix moved from a novelty to a widely used attack pattern that tricks users into running commands themselves, bypassing many endpoint defenses. Researchers said the technique n

Read more
CrashStealer malware abuses signed apps and fake crash-reporting prompts on macOS
18/07/2026
News
by Giuseppe

CrashStealer malware abuses signed apps and fake crash-reporting prompts on macOS

CrashStealer is a new macOS infostealer that disguises itself as Apple's crash-reporting tool and uses signed or notarized components to get past Gatekeeper checks. The malwar

Read more

Posts pagination

1 … 5 6 7
  • GitHub
  • LinkedIn
RSS Feeds
  • Articles FeedURL Copied!

Categories

  • API (1)
  • Artificial Intelligence (2)
  • CyberSec (4)
  • Development (2)
  • Hacking (1)
  • How To (9)
  • Malware Detection (1)
  • Members Only Content (2)
  • Mikrotik (2)
  • Mobile (2)
  • NetworkMonitoring (2)
  • NetworkSecurity (3)
  • News (67)
  • Privacy (2)
  • Programming (1)
  • Python (1)
  • RouterOS (1)
  • Security Tools (5)
  • Self-Hosting (2)
  • SMS (1)
  • Threat Hunting (1)
  • ThreatDetection (1)

Recent Posts

  • OpenAI: the models escaped the sandbox and hit Hugging Face
    by Giuseppe
    22/07/2026
  • Active exploit on SharePoint CVE-2026-50522 after Patch Tuesday
    by Giuseppe
    22/07/2026
  • ServiceNow AI Platform CVE-2026-6875: Unauthenticated RCE Already Exploited
    by Giuseppe
    22/07/2026
  • WordPress wp2shell: the exploit chain fueling mass scanning
    by Giuseppe
    22/07/2026
  • Qilin exploits CVE-2026-0257 in PAN-OS GlobalProtect to breach VPNs
    by Giuseppe
    22/07/2026

© 2026 SEC-TTL — All rights reserved

SEC-TTL is a cybersecurity news aggregator — sources are always credited and linked. Report / takedown · Copyright policy

  • News
  • How To
  • Members Area
  • About me
  • English
    • Italiano
    • Français
    • Deutsch
    • English