Section
Cybersecurity
Deep coverage of cybersecurity — benchmarks, launches and the long-form analysis we wish we had.
Showing 9 of 17

ShinyHunters Turned OAuth Consent Into a Master Key: The 2026 Salesforce Breach Wave
In July 2026 Microsoft detailed how ShinyHunters breached hundreds of Salesforce tenants through OAuth consent phishing, not stolen passwords. Here's how the ShinyHunters Salesforce OAuth campaign worked, who it hit, and how to defend your own SaaS stack.

SimpleHelp CVE-2026-48558: Max-Severity Auth Bypass Dropping Djinn Stealer Through MSPs. Patch to 5.5.16 Now
SimpleHelp CVE-2026-48558 is a CVSS 10.0 auth bypass on CISA's KEV list, already dropping Djinn Stealer via MSPs. Patch to 5.5.16 or 6.0 RC2 now.

Certighost (CVE-2026-54121): The AD CS Flaw That Lets Any Domain User Take Over Your Domain
Certighost (CVE-2026-54121) is a critical AD CS flaw, CVSS 8.8, that lets any low-privileged domain user impersonate a Domain Controller and seize the whole domain. Patched July 14; a working exploit went public July 24. Patch now.

wp2shell (CVE-2026-63030): A WordPress Core Pre-Auth RCE, and What to Do Now
wp2shell (CVE-2026-63030 + CVE-2026-60137) is a pre-authentication RCE in WordPress Core, already exploited in the wild. Here's who is affected, how the exploit chain works, how to patch, and how to check whether your server was already compromised.

New Langflow RCE (CVE-2026-10134) Is a Perfect 10 — Patch Now and Rotate Your Keys
CVE-2026-10134 is a CVSS 10.0 unauthenticated RCE in Langflow (versions 1.0.0 through 1.9.3) that lets attackers read every secret on the server. Here is the flaw, the pattern behind Langflow's 2026 RCEs, and how to patch.

SharePoint Zero-Day CVE-2026-58644: Patch Now and Rotate Your Machine Keys
SharePoint CVE-2026-58644 is a CVSS 9.8 remote-code-execution zero-day already exploited in the wild. CISA gave federal agencies until July 19, 2026 to patch on-prem SharePoint Server — and rotating your IIS machine keys matters as much as the patch.

Adobe ColdFusion CVE-2026-48282: A Max-Severity (CVSS 10) Bug Already Under Attack — Patch Now
CVE-2026-48282 is a CVSS 10.0 path-traversal flaw in Adobe ColdFusion that lets an unauthenticated attacker run code over the network. Adobe patched it June 30, 2026; it's already exploited and on CISA's KEV list. Here's what it is and how to respond.

Januscape (CVE-2026-53359): a 16-Year-Old KVM Flaw Lets VMs Escape the Host
Januscape (CVE-2026-53359) is a 16-year-old use-after-free in Linux KVM's shadow MMU that lets a guest VM escape to the host on Intel and AMD. Here's how the flaw works, who's exposed, and the patched kernel versions to deploy now.

RoguePlanet (CVE-2026-50656): Windows Defender Zero-Day Patched 29 Days After Public Exploit
RoguePlanet (CVE-2026-50656) is a Windows Defender zero-day that hands any local user SYSTEM control. Microsoft shipped the fix on July 9, 2026, nearly a month after working exploit code went public. Here is what it is, who is affected, and how to check your engine is patched.