📡 Tech & Security Digest — 2026-07-09
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- CISA orders feds to prioritize patching Langflow auth bypass flaw — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in th…
- Microsoft patches RoguePlanet Defender zero-day vulnerability — Microsoft has released a security patch to address a Defender zero-day vulnerability known as “RoguePlanet,” disclosed after the June 2026 Patch Tuesd…
- Hackers exploit Roundcube flaw to spy on academic researchers — A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backd…
- Ubiquiti warns of new max severity UniFi OS vulnerability — Ubiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in…
- Accenture confirms breach after hacker offers stolen data for sale — IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other dat…
- CISA orders feds to patch max severity ColdFusion flaw by Friday — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw …
- Chinese hackers develop LONGLEASH malware to expand ORB network — Chinese hackers tracked as ‘UAT-7810’ are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet…
- Mount Royal University confirms breach as hackers claim attack — Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university’s network. […..
Hacker News
- Patching MechCommander’s “left arm bug” for fun and profit (64 pts)
- John Deere owners will get the right to repair equipment under FTC settlement (796 pts)
- Cloudflare Drop (423 pts)
Krebs on Security
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure — Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig.
The vul…
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials — Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain…
- Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities — A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departm…
- New Avalon Malware Framework Packs CrownX Ransomware Capabilities — Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that’s distributed by means of a multi-…
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros — Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take …
- BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA — BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that…
- Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS — Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi O…
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) cat…
- Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants — Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artific…
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack — Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent.
Its Threat …