Help Net Security
helpnetsecurity · C · active
https://www.helpnetsecurity.com/
Tech press; useful for vendor reports and patch summaries. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.helpnetsecurity.com/ (listing) then webfetch per-article URL for body. AVOID: Nothing — WebFetch works on both listing and articles. High daily volume; many items are vendor-report/PR roundups, so triage to vuln/breach/threat items.. | 2026-07-05 admiralty audit: C — reputable security-news aggregator, mostly re-reports vendor/research findings; corroborate before acting. MEDIUM->C, stays active.
Cited in 50 entries
Citation cadence
Citation days per ISO week (10 weeks of coverage span, total 28).
- Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials2026-07-08
- CVE-2026-45659 — Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed2026-07-02
- Kaspersky GReAT: "StrikeShark" loader deploys Cobalt Strike via "Perfect DLL Hijacking" against government targets2026-06-27
- Klue/Icarus Salesforce OAuth breach — BeyondTrust and LastPass added to the named-victim list2026-06-25
- CVE-2026-50751 — Check Point Security Gateway IKEv1 VPN authentication bypass: public PoC, Qilin affiliate use2026-06-22
- CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813 — FortiSandbox: three critical flaws exploited in one 24-hour window2026-06-22
- Chaotic Eclipse / Nightmare Eclipse zero-day wave — RoguePlanet (CVE-2026-50656) still unpatched, PoC works on June builds2026-06-22
- Operation Endgame expands to SocGholish/TA569 — 106 C2 servers down, FakeUpdates loader stripped from 14,971 WordPress sites2026-06-19
- Nightmare/Chaotic Eclipse zero-day wave — the Defender LPE now carries a CVE, a public PoC, and Microsoft's "Exploitation More Likely" rating, with no patch2026-06-19
- ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer framework2026-06-19
- FortiSandbox — three critical flaws now exploited simultaneously, including the previously disclosure-only CVE-2026-250892026-06-17
- DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)2026-06-17
- CVE-2026-48907 — Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)2026-06-17
- Check Point IKEv1 CVE-2026-50751 — public PoC raises exploitation risk2026-06-17
- PRC UNC6508 ran year-plus espionage through internet-facing REDCap servers and a Google Workspace BCC rule2026-06-16
- France's Tchap government messenger breached via account takeover — 73,467 civil servants' metadata scraped, CNIL notified2026-06-10
- Check Point IKEv1 VPN Authentication Bypass (CVE-2026-50751)2026-06-09
- Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services2026-06-06
- Sophos finds an attacker-built, AI-orchestrated EDR-evasion testing lab during incident response2026-06-03
- CVE-2025-48595 — Android Framework: actively-exploited integer-overflow privilege escalation2026-06-03
- Windows Netlogon CVE-2026-41089 moves from "patch-available" to actively exploited2026-06-02
- Looking ahead — 2026-W232026-06-01
- CVE-2026-41089 — Windows Netlogon: pre-auth SYSTEM RCE on domain controllers, actively exploited2026-06-01
- CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: no-patch zero-day chain confirmed to push malicious configs to edge devices2026-06-01
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brands2026-05-29
- Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries2026-05-28
- FBI FLASH CSA 260526 — Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails2026-05-28
- Deleted Google Cloud API keys keep authenticating for up to 23 minutes2026-05-24
- FBI PSA260521 — Kali365 OAuth device-code PhaaS bypasses M365 MFA without credential capture2026-05-23
- Operation Saffron dismantles First VPN — 33+ servers seized, user database captured, Switzerland named JIT participant; Phobos RaaS infrastructure link confirmed2026-05-22
- Verizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 years2026-05-21
- TeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root cause2026-05-21
- INTERPOL Operation Ramz — 13-country MENA cybercrime sweep: 201 arrests, 53 servers seized, Algerian PhaaS server takedown2026-05-19
- Verizon 2026 DBIR — vulnerability exploitation is the #1 breach vector for the first time in 19 years; patching cadence regressed2026-05-18
- Sophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectors2026-05-15
- CVE-2026-46300 — Linux kernel: local privilege escalation via xfrm ESP-in-TCP ("Fragnesia"), PoC public2026-05-15
- CVE-2026-41089 / CVE-2026-41096 / CVE-2026-41103 / CVE-2026-42898 — Microsoft May 2026 Patch Tuesday (120+ CVEs, no zero-days)2026-05-13
- GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware2026-05-12
- BKA and ZIT dismantle relaunched Crimenetwork darknet marketplace; German operator arrested in Mallorca on European Arrest Warrant2026-05-12
- Sophos 2026 State of Identity Security — 71% of orgs breached via identity, 41% root-caused to non-human-identity mismanagement, Switzerland records highest incidence2026-05-11
- Looking ahead — 2026-W202026-05-11
- DAEMON Tools Lite supply chain — QUIC RAT deployed via signed installer; EU governments among targeted victims2026-05-09
- CVE-2026-43284 / CVE-2026-43500 — Linux "Dirty Frag": deterministic LPE chain via page-cache write primitives in xfrm-ESP and RxRPC, active exploitation confirmed2026-05-09
- Public-sector administration and digital identity (FR, EU, FI, CH)2026-05-04
- Looking ahead — 2026-W192026-05-04
- DigiCert support portal compromise — Salesforce-based support-chat social engineering yielded 60 fraudulent EV code-signing certificates2026-05-04
- DAEMON Tools Lite supply-chain compromise — China-nexus QUIC RAT delivered via signed installers; ~12 selective government / scientific / manufacturing targets2026-05-04
- CVE-2026-6973 + CVE-2026-5787 — Ivanti EPMM on-prem pre-auth chain to admin RCE; 508 EU instances internet-exposed; named EU victims include the European Commission2026-05-04
- CVE-2026-32202 — Windows Shell NTLM coercion; Akamai's PatchDiff-AI shows the residual zero-click path left by the CVE-2026-21510 patch2026-05-04
- cPanel / WHM — two emergency TSRs inside ten days: post-CVE-2026-41940 fleet now facing CVE-2026-29201/29202/292032026-05-04