Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw - Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Disclosure lists vBulletin...
An Open and Competitive AI Ecosystem - AI leadership depends on innovation, competition and choice. Michael Dell shares his perspective on the role of open-weight AI models, the importance of a competitive AI…
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update - Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management ( RMM ) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that...
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available - Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723 , the...
Ernst & Young data breach claimed by ShinyHunters extortion gang - The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack.