Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1577+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational

Tech News

Latest updates from the world of IT and cybersecurity

Search all news articles

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
NEWSJun 23, 2026

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests

A heap over-read vulnerability introduced in a 1997 FTP parser change allows a malicious co-user of a shared Squid proxy to read other users' cleartext HTTP requests, including authorization headers and session tokens.

4 min read
Read
Data Exposure Flaws in Dify AI Platform Put 1 Million+ App Tenants at Risk
NEWSJun 23, 2026

Data Exposure Flaws in Dify AI Platform Put 1 Million+ App Tenants at Risk

Security researchers discovered multi-tenant isolation failures in the Dify AI platform that allowed attackers to read private conversations from other tenants, preview their uploaded documents, and reach internal APIs — threatening the privacy of over one million applications built on the platform.

5 min read
Read
Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks
NEWSJun 23, 2026

Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks

A high-severity use-after-free vulnerability lurking in Samsung's KNOX security framework for eight years left Galaxy devices from the S9 through S25 series vulnerable to kernel-level attacks. The flaw has now been patched, but its longevity raises serious questions about security review processes in flagship device platforms.

6 min read
Read
FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist
NEWSJun 23, 2026

FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist

The FortiBleed campaign's operators weaponize Fortinet's own built-in diagnostic command to run a custom Golang sniffer that intercepts 24 authentication protocols — turning compromised FortiGate devices into self-sustaining credential harvesting platforms feeding 650+ parallel pipelines.

5 min read
Read
FortiBleed: Russian IAB Harvested 110 Million Credentials from 430,000 FortiGate Firewalls
NEWSJun 23, 2026

FortiBleed: Russian IAB Harvested 110 Million Credentials from 430,000 FortiGate Firewalls

A financially motivated Russian-speaking initial access broker behind the FortiBleed campaign has been systematically harvesting credentials from over 430,000 FortiGate firewalls worldwide since February 2026, amassing more than 110 million stolen credentials for sale on criminal markets.

5 min read
Read
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
NEWSJun 23, 2026

GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns

GitHub released actions/checkout v7 on June 18, 2026, adding default protections that refuse to fetch fork PR code inside pull_request_target workflows — closing a widely misused CI/CD privilege escalation vector responsible for secrets theft at Nx, PostHog, TanStack, and others.

4 min read
Read
LastPass Confirms Data Breach in Klue Supply Chain Attack
NEWSJun 23, 2026

LastPass Confirms Data Breach in Klue Supply Chain Attack

The Icarus extortion group compromised Klue, an AI-powered competitive intelligence platform, harvesting OAuth tokens to drain CRM data from hundreds of enterprise Salesforce environments — including LastPass, Huntress, HackerOne, and Recorded Future.

4 min read
Read
New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
NEWSJun 23, 2026

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

Elastic Security Labs has uncovered OXLOADER, a sophisticated new malware loader using malvertising via Google Ads to target developers searching for Node.js, ultimately deploying the CastleStealer information stealer with heavy obfuscation and anti-analysis techniques.

5 min read
Read
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
NEWSJun 23, 2026

OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

OpenAI has released GPT-5.5-Cyber, its most capable security model yet, as part of the Daybreak initiative — targeting real-world vulnerabilities in Chrome V8, Safari, Firefox, and critical open-source infrastructure like cURL and Python.

4 min read
Read