Adobe ColdFusion administrators woke up to an urgent warning this week: a critical path traversal vulnerability (CVE-2026-48282) is being actively exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on July 7, 2026, and issued a binding remediation timeline for federal agencies under BOD 26-04 that requires
Author: Saugata Datta
70% of WordPress Sites Running Outdated PHP Versions, Leaving Millions Exposed
A recent analysis of publicly accessible WordPress installations has revealed a startling reality: a large majority of sites are running PHP versions that are no longer supported, creating a widespread and avoidable security risk. While WordPress itself issues regular updates, the underlying server-side language many sites rely on—PHP—has lagged behind in adoption. The result is an ecosystem where millions of
Microsoft Extends Windows 10 Extended Security Updates Through October 2027
Microsoft has quietly extended its consumer Extended Security Updates (ESU) program for Windows 10, pushing the cutoff for critical security patches out another year to October 12, 2027. The move gives millions of users who have not yet migrated to Windows 11 additional time to receive important and critical security fixes, while Microsoft continues to encourage upgrades to the newer
Russia Used Cellebrite’s UFED to Breach an Activist’s iPhone — and the Tools Kept Working
In June 2021, Russian authorities seized the devices of opposition figure Andrey Pivovarov and, according to a forensic report later analyzed by Citizen Lab, used traces of Cellebrite’s Universal Forensic Extraction Device (UFED) to extract messages and search for political names. The case is striking because it appears to show forensic use of Cellebrite technology months after the company publicly
Photo ZIP Campaign Targets Hospitality Industry with Node.js Implant for Persistent Access
Microsoft Threat Intelligence has identified an active, multi-stage intrusion campaign that has targeted organizations in the hospitality and hotel industry since April 2026. Attackers delivered browser-downloaded photo-themed ZIP archives that contained executable shortcut files disguised as images. When opened, these shortcuts kicked off an obfuscated PowerShell chain that fetched a Node.js–based implant, established dual registry persistence, and initiated command-and-control (C2)
Palo Alto GlobalProtect CVE-2026-0257: Active Exploitation and Urgent Steps for Defenders
Palo Alto Networks has warned that a recently patched authentication bypass in PAN-OS GlobalProtect, tracked as CVE-2026-0257, is now being actively exploited in the wild. The vulnerability allows attackers to bypass authentication controls and establish unauthorized VPN connections when devices are configured with specific authentication override cookie and certificate settings. Organizations running GlobalProtect should treat this as urgent: apply vendor





