📡 Tech & Security Digest — 2026-07-12
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Hackers exploit critical auth bypass in Gitea Docker image — Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to i…
- Zimbra urges customers to patch critical web client XSS flaw — The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration su…
- Former ransomware negotiator gets 4 years for BlackCat attacks — A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat…
- Australia warns of global campaign targeting vulnerable CMS platforms — The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS)…
- New U-Boot flaws could enable stealthy firmware attacks — Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot,…
Hacker News
- Digital Deli, 1984 book by early PC hackers and enthusiasts (65 pts)
- Mesh LLM: distributed AI computing on iroh (216 pts)
- Under federal rule, colleges must leave grads better off or lose financial aid (61 pts)
- Fixed three bugs that made Qwen3.5-122B a daily driver on Mac Studio (50 pts)
- Female US rower completes historic solo journey from California to Hawaii (288 pts)
Krebs on Security
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges — Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.
Th…
- Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities — A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departm…
- Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws — Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully expl…
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros — Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take …
- BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA — BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that…
- Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets — Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how s…
- Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS — Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi O…
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) cat…
- Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants — Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artific…
- SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users — A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix l…