📡 Tech & Security Digest — 2026-07-07
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Max severity Adobe ColdFusion flaw now exploited in attacks — Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence comp…
- BeyondTrust warns of critical flaws in remote access software — BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could al…
Hacker News
- Januscape: Guest-to-Host Escape in KVM/x86 [CVE-2026-53359] (111 pts)
- The Private Capture of Public Genius (185 pts)
- GLM 5.2 and the coming AI margin collapse (405 pts)
- Small AI Models Gain Traction In places with unreliable networks (137 pts)
- AMD Ryzen AI Halo – $4k AI Dev Kit (326 pts)
- Linux on the Atari Jaguar (151 pts)
- OfficeCLI: Office suite for AI agents to read and edit Microsoft Office files (180 pts)
- NSA and IETF: Fairness (106 pts)
- Kani: A Model Checker for Rust (142 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure — Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig.
The vul…
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials — Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain…
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos — Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, tra…
- New Avalon Malware Framework Packs CrownX Ransomware Capabilities — Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that’s distributed by means of a multi-…
- Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts — A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from e…
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its …
- BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA — BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that…
- AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android — Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining “unrealistic bro…
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack — Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent.
Its Threat …
- Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service — Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Ga…