<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>CosmicBytez Labs</title>
    <link>https://labs.cosmicbytez.ca</link>
    <description>IT &amp; Cybersecurity Intelligence - News, Security Alerts, HOWTOs, and Project Guides</description>
    <language>en-ca</language>
    <lastBuildDate>Sun, 26 Jul 2026 02:42:46 GMT</lastBuildDate>
    <atom:link href="https://labs.cosmicbytez.ca/api/rss" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://labs.cosmicbytez.ca/images/icon.png</url>
      <title>CosmicBytez Labs</title>
      <link>https://labs.cosmicbytez.ca</link>
    </image>
    
    <item>
      <title><![CDATA[AegisAI Raises $36 Million for AI-Powered Email Security]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-25-aegisai-raises-36-million-for-ai-powered-email-security</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-25-aegisai-raises-36-million-for-ai-powered-email-security</guid>
      <description><![CDATA[AegisAI has closed a $36 million funding round led by Battery Ventures, Accel, and Foundation Capital, bringing the company's total raise to $49 million as demand accelerates for AI-native defenses against phishing and business email compromise.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AegisAI</category>
      <category>Email Security</category>
      <category>AI Security</category>
      <category>Funding</category>
      <category>Phishing</category>
      <category>BEC</category>
      <category>Venture Capital</category>
    </item>
    <item>
      <title><![CDATA[Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-25-cl0p-affiliates-target-internet-exposed-ptc-windchill-and-flexplm-with-unauthent</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-25-cl0p-affiliates-target-internet-exposed-ptc-windchill-and-flexplm-with-unauthent</guid>
      <description><![CDATA[Threat actors linked to the Cl0p ransomware group are actively exploiting chained pre-authentication vulnerabilities in PTC Windchill and FlexPLM deployments, achieving unauthenticated remote code execution as part of a data extortion campaign.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>Cl0p</category>
      <category>RCE</category>
      <category>PTC Windchill</category>
      <category>FlexPLM</category>
      <category>Industrial Security</category>
      <category>Data Extortion</category>
      <category>Cybercrime</category>
    </item>
    <item>
      <title><![CDATA[DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-25-devman-raas-portal-centralizes-payload-builds-victim-management-and-affiliate-pa</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-25-devman-raas-portal-centralizes-payload-builds-victim-management-and-affiliate-pa</guid>
      <description><![CDATA[PRODAFT has published detailed analysis of the DevMan ransomware-as-a-service operation, revealing a professional-grade affiliate portal with payload builders, victim lifecycle management, churn requirements, and an 80/20 revenue split — plus a disturbing Huntress insider leak angle.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>DevMan</category>
      <category>RaaS</category>
      <category>PRODAFT</category>
      <category>Cybercrime</category>
      <category>Funky Mantis</category>
      <category>ChaCha20</category>
    </item>
    <item>
      <title><![CDATA[Fastjson 1.x RCE Actively Exploited With No Patch Available]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-25-fastjson-1x-rce-vulnerability-targeted-in-attacks-with-no-patched-available</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-25-fastjson-1x-rce-vulnerability-targeted-in-attacks-with-no-patched-available</guid>
      <description><![CDATA[Attackers are actively exploiting CVE-2026-16723, a critical remote code execution flaw in Alibaba's Fastjson 1.x library affecting Spring Boot applications. No patched version of Fastjson 1.x exists — and exploitation began within days of disclosure.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Vulnerability</category>
      <category>CVE-2026-16723</category>
      <category>Fastjson</category>
      <category>Spring Boot</category>
      <category>Java</category>
      <category>RCE</category>
      <category>Active Exploitation</category>
      <category>Security Updates</category>
    </item>
    <item>
      <title><![CDATA[SourTrade: Malicious Sites Use JavaScript to Assemble Malware Directly in Browser Memory]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-25-malicious-sites-use-javascript-to-build-malware-in-browser-memory</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-25-malicious-sites-use-javascript-to-build-malware-in-browser-memory</guid>
      <description><![CDATA[The SourTrade malvertising campaign impersonates Solana, Luno, and TradingView to deliver malware assembled entirely inside browser memory using JavaScript service workers — meaning the finished binary never touches the network and evades all network-based detection.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Malware</category>
      <category>Malvertising</category>
      <category>SourTrade</category>
      <category>JavaScript</category>
      <category>ServiceWorker</category>
      <category>Browser Security</category>
      <category>Crypto</category>
    </item>
    <item>
      <title><![CDATA[Microsoft, Tech Companies Throw Weight Behind Spread of Open-Source AI]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-25-microsoft-tech-companies-throw-weight-behind-spread-of-open-source-ai</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-25-microsoft-tech-companies-throw-weight-behind-spread-of-open-source-ai</guid>
      <description><![CDATA[Microsoft, Meta, NVIDIA, IBM, Palantir, Perplexity, Mistral, Mozilla, The Linux Foundation, Hugging Face, and Dell Technologies have co-signed a letter backing the spread of open-source AI, signaling a broad industry coalition for transparent AI development.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Microsoft</category>
      <category>Open Source</category>
      <category>AI Policy</category>
      <category>Meta</category>
      <category>NVIDIA</category>
      <category>Linux Foundation</category>
      <category>Hugging Face</category>
      <category>AI Governance</category>
    </item>
    <item>
      <title><![CDATA[Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-25-researcher-publishes-gitlab-rce-poc-letting-authenticated-users-run-commands-as-git</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-25-researcher-publishes-gitlab-rce-poc-letting-authenticated-users-run-commands-as-git</guid>
      <description><![CDATA[Security researcher Yuhang Wu published a working PoC exploiting two Ruby memory corruption vulnerabilities in the Oj JSON parser to achieve RCE as the git user on unpatched GitLab self-managed instances via crafted Jupyter notebook diffs.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>GitLab</category>
      <category>RCE</category>
      <category>PoC</category>
      <category>CVE-2026-54502</category>
      <category>Ruby</category>
      <category>Jupyter</category>
      <category>Memory Corruption</category>
      <category>DevSecOps</category>
    </item>
    <item>
      <title><![CDATA[ShinyHunters Data Leaks Fuel $2,000 Sextortion Email Scam]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-25-shinyhunters-data-leaks-fuel-2000-sextortion-email-scam</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-25-shinyhunters-data-leaks-fuel-2000-sextortion-email-scam</guid>
      <description><![CDATA[Threat actors are leveraging email addresses exposed in ShinyHunters data breaches to send highly personalized sextortion emails demanding $2,000 in Bitcoin, exploiting victim trust by referencing real leaked credentials.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Sextortion</category>
      <category>ShinyHunters</category>
      <category>Phishing</category>
      <category>Social Engineering</category>
      <category>Bitcoin</category>
      <category>Cybercrime</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-15704: Critical Auth Bypass in Eclipse BaSyx Go Components]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-15704</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-15704</guid>
      <description><![CDATA[Eclipse BaSyx Go Components up to v1.0.0 contains a CVSS 9.8 authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router, allowing unauthenticated access to protected endpoints.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-15704</category>
      <category>Eclipse BaSyx</category>
      <category>Authorization Bypass</category>
      <category>Go</category>
      <category>ABAC</category>
      <category>IoT</category>
      <category>ICS</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-56163: Critical Auth Bypass in Azure Kubernetes Service Allows Privilege Escalation]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-56163</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-56163</guid>
      <description><![CDATA[A CVSS 10.0 vulnerability in Microsoft Azure Kubernetes Service allows unauthenticated attackers to escalate privileges over the network due to missing authentication for a critical function.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>Microsoft</category>
      <category>Azure</category>
      <category>Kubernetes</category>
      <category>Cloud Security</category>
      <category>Privilege Escalation</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-57106: Critical SSRF in SAP Data Quality Enables Unauthenticated Privilege Escalation]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-57106</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-57106</guid>
      <description><![CDATA[A CVSS 10.0 server-side request forgery vulnerability in SAP Data Quality Management allows an unauthenticated attacker to escalate privileges over the network, posing a critical risk to enterprise SAP deployments.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>SAP</category>
      <category>SSRF</category>
      <category>Privilege Escalation</category>
      <category>Enterprise Security</category>
      <category>Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-61884: Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass (CVSS 9.8)]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-61884</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-61884</guid>
      <description><![CDATA[A critical authentication bypass in the Tycon Systems TPDIN-Monitor-WEB2 web interface allows unauthenticated remote attackers to gain full administrative access by submitting empty credentials — no exploit code required.]]></description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-61884</category>
      <category>ICS</category>
      <category>OT</category>
      <category>Authentication Bypass</category>
      <category>CISA</category>
      <category>Tycon Systems</category>
      <category>Power Management</category>
    </item>
    <item>
      <title><![CDATA[AegisAI Raises $36 Million to Fight AI-Crafted Phishing with AI Defenses]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-24-aegisai-raises-36-million-for-ai-powered-email-security</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-24-aegisai-raises-36-million-for-ai-powered-email-security</guid>
      <description><![CDATA[AegisAI has closed a $36M Series A, bringing total funding to $49M, to scale its AI agent-based email security platform purpose-built to counter the rise of AI-generated phishing and business email compromise attacks.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI Security</category>
      <category>Email Security</category>
      <category>Phishing</category>
      <category>Funding</category>
      <category>Startup</category>
      <category>BEC</category>
    </item>
    <item>
      <title><![CDATA[ChatGPT 'AgentForger' Flaw Could Deploy Rogue Workspace Agents via a Phishing Link]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-24-chatgpt-agentforger-flaw-could-deploy-rogue-workspace-agents-via-a-phishing-link</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-24-chatgpt-agentforger-flaw-could-deploy-rogue-workspace-agents-via-a-phishing-link</guid>
      <description><![CDATA[Zenity Labs disclosed a critical cross-site agent forgery vulnerability in ChatGPT's Workspace Agent Builder that let a single phishing link silently create an autonomous AI agent inside a victim's organization — inheriting their identity, connectors, and permissions.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI security</category>
      <category>ChatGPT</category>
      <category>vulnerability</category>
      <category>agentic AI</category>
      <category>phishing</category>
      <category>OpenAI</category>
    </item>
    <item>
      <title><![CDATA[Chick-fil-A Data Breach Affects More Than 13,000 Customers]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-24-chick-fil-a-data-breach-affects-more-than-13000-customers</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-24-chick-fil-a-data-breach-affects-more-than-13000-customers</guid>
      <description><![CDATA[Credential stuffing attacks hit Chick-fil-A One loyalty accounts in June 2026, exposing names, stored credit balances, mobile pay QR codes, and partial card data for over 13,000 customers.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>data breach</category>
      <category>credential stuffing</category>
      <category>loyalty programs</category>
      <category>consumer security</category>
    </item>
    <item>
      <title><![CDATA[Clop Ransomware Targets PTC Windchill and FlexPLM in Mass Data Theft Campaign]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-24-clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-24-clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks</guid>
      <description><![CDATA[The Clop ransomware gang is exploiting CVE-2026-12569, a critical unauthenticated RCE flaw (CVSS 9.8) in PTC Windchill and FlexPLM, deploying webshells to exfiltrate sensitive product data from aerospace, automotive, and manufacturing organizations.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>ransomware</category>
      <category>clop</category>
      <category>vulnerability</category>
      <category>CVE-2026-12569</category>
      <category>supply chain</category>
      <category>manufacturing</category>
    </item>
    <item>
      <title><![CDATA[Hermes AI Agent Used to Automate Attack on Thai Finance Ministry]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-24-hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-24-hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry</guid>
      <description><![CDATA[A threat actor deployed the open-source Hermes AI agent in unattended 'YOLO' mode to autonomously conduct post-exploitation against Thailand's Ministry of Finance — scanning for kernel CVEs, enumerating the filesystem, and crawling the web root for sensitive documents, all without human intervention.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI Security</category>
      <category>Threat Intelligence</category>
      <category>Post-Exploitation</category>
      <category>Government</category>
      <category>Agentic AI</category>
      <category>Nation State</category>
    </item>
    <item>
      <title><![CDATA[In Other News: Dolphin X AI Malware, Car Anti-Theft Hack, 432 Linux Kernel CVEs]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-24-in-other-news-dolphin-x-ai-powered-malware-car-anti-theft-device-hack-400-linux-</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-24-in-other-news-dolphin-x-ai-powered-malware-car-anti-theft-device-hack-400-linux-</guid>
      <description><![CDATA[This week's security roundup covers an AI-prioritizing infostealer targeting developer machines, a hardcoded Bluetooth key in 2.2 million car anti-theft units, a single-day flood of 432 Linux kernel CVEs, and ongoing threats from Siemens ICS zero-days and Russian Zimbra espionage.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Malware</category>
      <category>Linux</category>
      <category>IoT</category>
      <category>Ransomware</category>
      <category>Russia</category>
      <category>ICS</category>
      <category>Cybercrime</category>
      <category>Threat Intelligence</category>
    </item>
    <item>
      <title><![CDATA[Kimi K3 AI Agents Discovered Redis Zero-Days and Built RCE Exploits in Under 90 Minutes]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-24-kimi-k3-agents-found-redis-zero-days-and-built-rce-exploit-researchers-say</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-24-kimi-k3-agents-found-redis-zero-days-and-built-rce-exploit-researchers-say</guid>
      <description><![CDATA[Autonomous AI agents powered by Moonshot AI's Kimi K3 model found 19 Redis zero-day vulnerabilities and produced working authenticated RCE proof-of-concept exploits in roughly 90 minutes, prompting Redis to ship seven security releases on July 23, 2026.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI Security</category>
      <category>Zero-Day</category>
      <category>Redis</category>
      <category>RCE</category>
      <category>Kimi K3</category>
      <category>Autonomous Agents</category>
      <category>Vulnerability Research</category>
    </item>
    <item>
      <title><![CDATA[NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-24-nodebb-patches-eight-ai-found-flaws-exposing-admin-access-and-private-chats</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-24-nodebb-patches-eight-ai-found-flaws-exposing-admin-access-and-private-chats</guid>
      <description><![CDATA[Aikido Security's AI pentest agents audited NodeBB forum software in just six hours and surfaced eight high-severity vulnerabilities — including admin dashboard bypass, private message exposure, and malicious code injection via fediverse federation.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>NodeBB</category>
      <category>AI Security</category>
      <category>Vulnerability</category>
      <category>Forum Software</category>
      <category>Fediverse</category>
      <category>Security Updates</category>
    </item>
    <item>
      <title><![CDATA[OnTrac Notifies Customers of Data Breach After Network Hack]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-24-ontrac-notifies-customers-of-data-breach-after-network-hack</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-24-ontrac-notifies-customers-of-data-breach-after-network-hack</guid>
      <description><![CDATA[US parcel delivery company OnTrac has begun notifying over 40,000 customers that hackers breached its corporate network in April 2025, exposing Social Security numbers, dates of birth, government-issued IDs, and health information.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Supply Chain</category>
      <category>Identity Theft</category>
      <category>Personal Data</category>
      <category>Logistics</category>
    </item>
    <item>
      <title><![CDATA[Seeing AI Agents Is Not Enough — Security Teams Must Enforce What They Can Do]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-24-seeing-ai-agents-is-not-enough-security-teams-must-enforce-what-they-can-do</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-24-seeing-ai-agents-is-not-enough-security-teams-must-enforce-what-they-can-do</guid>
      <description><![CDATA[Visibility into AI agents is a starting point, not a security control. Security teams need to move from agent discovery to enforcement — defining granular, purpose-driven controls across every platform where agents operate.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI security</category>
      <category>agentic AI</category>
      <category>governance</category>
      <category>least privilege</category>
      <category>identity security</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-12877: Critical SQL Injection in WordPress Project Management Plugin]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-12877</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-12877</guid>
      <description><![CDATA[An unauthenticated SQL injection flaw with a CVSS score of 9.1 affects the Project Management, Bug and Issue Tracking Plugin for WordPress before version 5.1.0, allowing attackers to read and modify sensitive project data without any credentials.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>WordPress</category>
      <category>SQL Injection</category>
      <category>Vulnerability</category>
      <category>Web Security</category>
    </item>
    <item>
      <title><![CDATA[GoDAM WordPress Plugin Arbitrary File Upload — CVE-2026-14282]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-14282</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-14282</guid>
      <description><![CDATA[A critical unauthenticated arbitrary file upload vulnerability in the GoDAM WordPress media library plugin allows attackers to upload malicious files and achieve remote code execution on affected sites running versions up to 1.12.2.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-14282</category>
      <category>WordPress</category>
      <category>File Upload</category>
      <category>RCE</category>
      <category>Plugin Vulnerability</category>
      <category>Critical</category>
    </item>
    <item>
      <title><![CDATA[WordPress Helpdesk Plugin Unauthenticated Code Injection — CVE-2026-15011]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-15011</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-15011</guid>
      <description><![CDATA[A critical unauthenticated PHP code injection vulnerability in the Customer Support Ticket System & Helpdesk WordPress plugin allows attackers to execute arbitrary PHP functions via a publicly accessible 'path' parameter, affecting all versions up to 6.0.5.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-15011</category>
      <category>WordPress</category>
      <category>Code Injection</category>
      <category>RCE</category>
      <category>Plugin Vulnerability</category>
      <category>Critical</category>
      <category>Unauthenticated</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-15981: WordPress SAML SSO Authentication Bypass (CVSS 9.8)]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-15981</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-15981</guid>
      <description><![CDATA[A critical authentication bypass in the WordPress SAML Single Sign On plugin allows unauthenticated attackers to log in as any user, including administrators, by exploiting a loose boolean check on PHP's openssl_verify() return value.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>WordPress</category>
      <category>SAML</category>
      <category>Authentication Bypass</category>
      <category>Critical</category>
      <category>Web Application Security</category>
    </item>
    <item>
      <title><![CDATA[fastjson RCE Without Gadget or AutoType — CVE-2026-16723]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-16723</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-16723</guid>
      <description><![CDATA[A critical remote code execution flaw in fastjson 1.2.68–1.2.83 requires no AutoType enablement and no classpath gadget, making it exploitable on virtually every default Spring Boot deployment.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-16723</category>
      <category>fastjson</category>
      <category>RCE</category>
      <category>Java</category>
      <category>Spring Boot</category>
      <category>Deserialization</category>
      <category>Critical</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-47724: nebula-mesh API Authorization Bypass Enables Cross-Tenant Takeover (CVSS 9.9)]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-47724</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-47724</guid>
      <description><![CDATA[A critical authorization bypass in nebula-mesh, the self-hosted control plane for Slack's Nebula VPN, allows any holder of a non-admin operator API key to access all other tenants' hosts, firewall rules, network configs, and mobile bundles. Fixed in v0.3.4.]]></description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>VPN</category>
      <category>Authorization Bypass</category>
      <category>API Security</category>
      <category>Critical</category>
      <category>Nebula</category>
    </item>
    <item>
      <title><![CDATA[Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-23-adobe-acrobat-extension-flaw-let-malicious-sites-read-whatsapp-web-data</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-23-adobe-acrobat-extension-flaw-let-malicious-sites-read-whatsapp-web-data</guid>
      <description><![CDATA[Researchers at Guardio disclosed a now-patched vulnerability chain in the Adobe Acrobat Chrome extension dubbed HermeticReader, which could allow malicious websites to silently hijack WhatsApp Web messages and contacts for over 314 million users.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Vulnerability</category>
      <category>Chrome</category>
      <category>Browser Extension</category>
      <category>WhatsApp</category>
      <category>Adobe</category>
      <category>Privacy</category>
      <category>Data Exposure</category>
    </item>
    <item>
      <title><![CDATA[Check Point Patches SmartConsole Zero-Day Exploited in Attacks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-23-check-point-warns-of-smartconsole-zero-day-exploited-in-attacks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-23-check-point-warns-of-smartconsole-zero-day-exploited-in-attacks</guid>
      <description><![CDATA[Check Point Software has patched an actively exploited zero-day vulnerability in its SmartConsole GUI admin panel. The flaw allowed attackers to compromise firewall management infrastructure — a high-value target for advanced threat actors.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Zero-Day</category>
      <category>Check Point</category>
      <category>Firewall</category>
      <category>Network Security</category>
      <category>Vulnerability</category>
      <category>Patch</category>
    </item>
    <item>
      <title><![CDATA[EU Fines Google $1 Billion for Search and App Store DMA Violations]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-23-eu-fines-google-1-billion-for-search-app-store-antitrust-violations</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-23-eu-fines-google-1-billion-for-search-app-store-antitrust-violations</guid>
      <description><![CDATA[The European Commission has issued Google its first Digital Markets Act fine — €890 million (~$1 billion USD) — split between Google Search self-preferencing abuses and Play Store restrictions on app developers.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Google</category>
      <category>European Union</category>
      <category>Antitrust</category>
      <category>Digital Markets Act</category>
      <category>Regulation</category>
      <category>Big Tech</category>
    </item>
    <item>
      <title><![CDATA[Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-23-hackers-exploit-windmill-flaw-to-read-arbitrary-server-files-without-authenticat</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-23-hackers-exploit-windmill-flaw-to-read-arbitrary-server-files-without-authenticat</guid>
      <description><![CDATA[A high-severity path traversal vulnerability in the open-source developer platform Windmill (CVE-2026-29059, CVSS 7.5) is under active exploitation, allowing unauthenticated attackers to read arbitrary files from the server — including credentials and config files.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Vulnerability</category>
      <category>CVE</category>
      <category>Path Traversal</category>
      <category>Windmill</category>
      <category>Developer Tools</category>
      <category>Unauthenticated</category>
      <category>Active Exploitation</category>
    </item>
    <item>
      <title><![CDATA[Russian Laundry Bear Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-23-laundry-bear-zimbra-zero-day</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-23-laundry-bear-zimbra-zero-day</guid>
      <description><![CDATA[A Russian state-sponsored espionage group spent months silently reading Western mailboxes through a zero-click XSS flaw in Zimbra's webmail client — stealing emails, 2FA tokens, and backup scratch codes that bypassed MFA resets.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Zero-Day</category>
      <category>Russia</category>
      <category>APT</category>
      <category>Zimbra</category>
      <category>Email Security</category>
      <category>XSS</category>
      <category>Espionage</category>
      <category>CISA</category>
      <category>The Hacker News</category>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title><![CDATA[msaRAT: Chaos Ransomware's New Backdoor Hides C2 Traffic Inside Chrome and Edge]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-23-msarat-browser-c2</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-23-msarat-browser-c2</guid>
      <description><![CDATA[Cisco Talos has uncovered msaRAT, a Rust-based remote access trojan deployed by the Chaos ransomware group that routes all command-and-control traffic through Chrome or Edge via WebRTC — making it nearly invisible to network defenders.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Malware</category>
      <category>Ransomware</category>
      <category>RAT</category>
      <category>Chrome</category>
      <category>Edge</category>
      <category>C2</category>
      <category>Evasion</category>
      <category>Chaos</category>
      <category>Cisco Talos</category>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title><![CDATA[Origin Energy Data Breach Exposes Millions of Australian Customers]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-23-origin-energy-data-breach</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-23-origin-energy-data-breach</guid>
      <description><![CDATA[Australia's largest energy retailer has confirmed a data breach affecting up to 2 million customers, with exposed data including full names, contact details, account information, and partial payment data.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Australia</category>
      <category>Energy Sector</category>
      <category>PII</category>
      <category>Critical Infrastructure</category>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title><![CDATA[Swiss Rail Giant Stadler Refuses $12.3M Ransom Demand from Everest Group]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-23-swiss-train-maker-stadler-refuses-everest-12-million-ransomware-demand</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-23-swiss-train-maker-stadler-refuses-everest-12-million-ransomware-demand</guid>
      <description><![CDATA[Stadler Rail has publicly rejected a CHF 10 million (~$12.3M USD) ransom demand from the Everest extortion group following a breach of a supplier data-exchange platform. The company filed a criminal complaint instead of paying.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>Everest</category>
      <category>Stadler</category>
      <category>Cybercrime</category>
      <category>Extortion</category>
      <category>Switzerland</category>
    </item>
    <item>
      <title><![CDATA[Upbound Group Data Breach Triggers $13M in Fraudulent Acima Lease Losses]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-23-upbound-group-says-data-breach-led-to-13-million-in-fraudulent-contract-losses</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-23-upbound-group-says-data-breach-led-to-13-million-in-fraudulent-contract-losses</guid>
      <description><![CDATA[Rent-A-Center parent Upbound Group (NASDAQ: UPBD) disclosed in an SEC 8-K filing that a data breach resulted in approximately $13 million in fraudulent Acima lease-to-own contracts during Q2 2026.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Fraud</category>
      <category>SEC Disclosure</category>
      <category>Acima</category>
      <category>Upbound</category>
      <category>Financial Impact</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-14291: WordPress Security Ninja Premium 2FA Authentication Bypass]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-14291</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-14291</guid>
      <description><![CDATA[The Security Ninja Premium WordPress plugin before version 5.290 contains a critical authentication flaw that allows attackers to bypass two-factor authentication, including for administrator accounts.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>WordPress</category>
      <category>Authentication Bypass</category>
      <category>2FA</category>
      <category>Plugin Vulnerability</category>
      <category>NVD</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-16606: Critical Pre-Auth RCE in Fujitsu openFT (CVSS 9.8)]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-16606</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-16606</guid>
      <description><![CDATA[A critical unauthenticated remote code execution vulnerability in Fujitsu Software openFT allows attackers to execute arbitrary code on Linux and Solaris systems without any authentication.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-16606</category>
      <category>Fujitsu</category>
      <category>RCE</category>
      <category>Linux</category>
      <category>Critical</category>
      <category>Pre-Auth</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-50522-microsoft-sharepoint-deserialization-of-untrusted-data-vulnerabil</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-50522-microsoft-sharepoint-deserialization-of-untrusted-data-vulnerabil</guid>
      <description><![CDATA[Microsoft SharePoint contains a critical deserialization of untrusted data vulnerability allowing unauthenticated attackers to execute arbitrary code over a network. Added to CISA's Known Exploited Vulnerabilities catalog on July 22, 2026.]]></description>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Vulnerability</category>
      <category>CVE</category>
      <category>Microsoft</category>
      <category>SharePoint</category>
      <category>CISA KEV</category>
      <category>Deserialization</category>
      <category>Remote Code Execution</category>
    </item>
    <item>
      <title><![CDATA[Chick-fil-A Discloses Data Breach After Credential Stuffing Attacks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-22-chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-22-chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks</guid>
      <description><![CDATA[Chick-fil-A is notifying customers across 10 states after credential stuffing attacks between June 17–19, 2026 compromised One loyalty accounts, exposing names, emails, QR codes, and partial payment data.]]></description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Credential Stuffing</category>
      <category>Chick-fil-A</category>
      <category>Loyalty Accounts</category>
      <category>Account Takeover</category>
      <category>Consumer Security</category>
    </item>
    <item>
      <title><![CDATA[Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-22-endpoint-security-firm-glow-launches-with-180m-in-funding-at-12b-valuation</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-22-endpoint-security-firm-glow-launches-with-180m-in-funding-at-12b-valuation</guid>
      <description><![CDATA[AI-native endpoint security startup Glow has launched from stealth with $180M in Series A funding and a $1.2B valuation. The firm uses environment mapping, risk analysis, and automated policy enforcement to deliver adaptive prevention across enterprise endpoints.]]></description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Endpoint Security</category>
      <category>AI Security</category>
      <category>Startup</category>
      <category>Funding</category>
      <category>Venture Capital</category>
      <category>Adaptive Security</category>
    </item>
    <item>
      <title><![CDATA[How Enterprise GenAI Can Amplify Ransomware Risk — and How to Contain It]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-22-how-enterprise-genai-can-amplify-ransomware-risk-and-how-to-contain-it</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-22-how-enterprise-genai-can-amplify-ransomware-risk-and-how-to-contain-it</guid>
      <description><![CDATA[Enterprise AI assistants and agents that inherit excessive permissions or compromised identities create new ransomware attack paths. Identity controls, least-privilege access, and AI governance are now frontline defenses.]]></description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>Generative AI</category>
      <category>AI Security</category>
      <category>Identity Security</category>
      <category>Enterprise Security</category>
      <category>Cybercrime</category>
    </item>
    <item>
      <title><![CDATA[South Korea Discloses Data Breach Impacting Diplomats Worldwide]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-22-south-korea-discloses-data-breach-impacting-diplomats-worldwide</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-22-south-korea-discloses-data-breach-impacting-diplomats-worldwide</guid>
      <description><![CDATA[South Korea's Ministry of Foreign Affairs has disclosed a data breach affecting approximately 10,000 diplomatic records after an unidentified attacker exploited a zero-day vulnerability in the Korea National Diplomatic Academy's online training platform, maintaining undetected access for roughly 10 months between April 2025 and February 2026.]]></description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Nation-State</category>
      <category>Espionage</category>
      <category>Zero-Day</category>
      <category>South Korea</category>
      <category>North Korea</category>
    </item>
    <item>
      <title><![CDATA[Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-22-suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-22-suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts</guid>
      <description><![CDATA[Two major data breaches came to light this week: AI music platform Suno had 55.3 million accounts exposed after a supply-chain worm compromised developer credentials in November 2025, while gig-work platform Paidwork saw 23 million accounts — including banking details — leaked publicly from a March 2026 intrusion.]]></description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Supply Chain</category>
      <category>AI Platform</category>
      <category>FinTech</category>
      <category>npm</category>
      <category>Have I Been Pwned</category>
    </item>
    <item>
      <title><![CDATA[Swiss Rail Giant Stadler Rejects $12.3M Ransom Demand After Cyberattack]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-22-swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-22-swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack</guid>
      <description><![CDATA[Swiss rail vehicle manufacturer Stadler Rail has publicly refused to pay a CHF 10 million (~$12.3M USD) ransom demanded by the Everest ransomware group after attackers breached a third-party supplier file-sharing platform and stole internal business documents.]]></description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>Data Breach</category>
      <category>Cybercrime</category>
      <category>Critical Infrastructure</category>
      <category>Supply Chain</category>
    </item>
    <item>
      <title><![CDATA[Upbound Says Hack Caused $13 Million in Fraudulent Acima Leases]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-07-22-upbound-says-hack-caused-13-million-in-fraudulent-acima-leases</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-07-22-upbound-says-hack-caused-13-million-in-fraudulent-acima-leases</guid>
      <description><![CDATA[The Upbound Group disclosed that a cybersecurity breach exposed customer data later used by threat actors to open $13 million in fraudulent Acima lease-to-own agreements during Q2 2026.]]></description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Fintech</category>
      <category>Fraud</category>
      <category>Acima</category>
      <category>Upbound</category>
      <category>Threat Intelligence</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-16232: Check Point SmartConsole Improper Authentication]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-16232-check-point-smartconsole-improper-authentication-vulnerability</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-16232-check-point-smartconsole-improper-authentication-vulnerability</guid>
      <description><![CDATA[A critical improper authentication flaw in Check Point SmartConsole allows unauthenticated remote attackers to steal login tokens and gain full admin access. Added to CISA KEV — patch immediately.]]></description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Check Point</category>
      <category>CVE-2026-16232</category>
      <category>Authentication Bypass</category>
      <category>CISA KEV</category>
      <category>Network Security</category>
      <category>Privilege Escalation</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-28302: SolarWinds Serv-U IDOR Leads to Root RCE]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-28302</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-28302</guid>
      <description><![CDATA[A critical CVSS 9.1 vulnerability in SolarWinds Serv-U allows group administrators to exploit an insecure direct object reference flaw to escalate privileges and achieve remote code execution as root on Linux deployments.]]></description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>SolarWinds</category>
      <category>Serv-U</category>
      <category>IDOR</category>
      <category>Privilege Escalation</category>
      <category>RCE</category>
      <category>CVE-2026-28302</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-62415: Joomla Membership Pro Allows Unauthenticated File Upload]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-62415</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-62415</guid>
      <description><![CDATA[The Joomla extension Membership Pro prior to version 4.6.2 allowed unauthenticated users to upload media assets by default, exposing sites to potential webshell deployment and compromise. CVSS 9.1 — upgrade now.]]></description>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Joomla</category>
      <category>CVE-2026-62415</category>
      <category>File Upload</category>
      <category>Unauthenticated</category>
      <category>Web Security</category>
      <category>NVD</category>
    </item>
  </channel>
</rss>