📡 Tech & Security Digest — 2026-07-13
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Hackers exploit critical auth bypass in Gitea Docker image — Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to i…
- Zimbra urges customers to patch critical web client XSS flaw — The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration su…
- Former ransomware negotiator gets 4 years for BlackCat attacks — A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat…
- Australia warns of global campaign targeting vulnerable CMS platforms — The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS)…
- New U-Boot flaws could enable stealthy firmware attacks — Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot,…
Hacker News
- GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years (258 pts)
- Ask HN: Add flag for AI-generated articles (612 pts)
- First look at Quest, the final ship of Antarctic explorer Shackleton (32 pts)
- Migrating a production AI agent to GPT-5.6: 2.2x faster, 27% cheaper (199 pts)
Krebs on Security
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges — Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.
Th…
- Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities — A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departm…
- Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws — Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully expl…
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros — Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take …
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensio…
- Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets — Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how s…
- Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS — Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi O…
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) cat…
- Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants — Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artific…
- SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users — A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix l…