Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
The Archive

Back Issues

Every weekly digest filed by the desk, preserved for the record.

15 editions · 689 stories indexed
  1. 31
    Vol. 2026
    Current Issue27 July – 2 August 2026

    Critical ServiceNow code execution flaw now exploited in attacks

    • Autonomous AI Intrusions Are Here: Lessons from the Hugging Face Compromise
    • New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
    19
    stories filed
    Open issue →
  2. 30
    Vol. 2026
    Back Issue20 – 26 July 2026

    EU sanctions Russian GRU military hackers over cyberattacks

    • UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
    • WordPress Core "wp2shell" RCE flaws get public exploits, patch now
    27
    stories filed
    Open issue →
  3. 29
    Vol. 2026
    Back Issue13 – 19 July 2026

    EU takes member states to court over unimplemented cybersecurity law

    • Compromised AsyncAPI npm packages: inside a CI supply-chain attack
    • Mako: A Self-Evolving Agentic Operating System (SE-AOS) for Autonomous Web Exploitation
    27
    stories filed
    Open issue →
  4. 28
    Vol. 2026
    Back Issue6 – 12 July 2026

    Supreme Court decision threatens EU-US data transfer agreement

    • CISA: Microsoft SharePoint RCE flaw now actively exploited
    • New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
    54
    stories filed
    Open issue →
  5. 27
    Vol. 2026
    Back Issue29 June – 5 July 2026

    Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond

    • Lazarus Group's Latest: Brandjacking Campaign on npm
    • Europe Evolves Into Ransomware's Favorite Region
    31
    stories filed
    Open issue →
  6. 26
    Vol. 2026
    Back Issue22 – 28 June 2026

    We beat Google’s zero-knowledge proof of quantum cryptanalysis

    • Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model
    • V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory
    82
    stories filed
    Open issue →
  7. 25
    Vol. 2026
    Back Issue15 – 21 June 2026

    New GitHub Action supply chain attack: reviewdog/action-setup

    • [NEU] [hoch] VMware Tanzu Spring Cloud Gateway Server und Sleuth: Mehrere Schwachstellen
    • Software Dark Matter: Gazing at Uncharted Files to Navigate SBOM Integrations
    82
    stories filed
    Open issue →
  8. 24
    Vol. 2026
    Back Issue8 – 14 June 2026

    s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know

    • EU unveils tech sovereignty package to cut reliance on US, Chinese suppliers
    • Critical vulnerabilities in NetScaler ADC exploited in-the-wild: everything you need to know
    70
    stories filed
    Open issue →
  9. 23
    Vol. 2026
    Back Issue1 – 7 June 2026

    [NEU] [UNGEPATCHT] [kritisch] Gogs: Schwachstelle ermöglicht Codeausführung

    • [NEU] [hoch] vllm: Schwachstelle ermöglicht Codeausführung
    • When AI Meets Wall Street: A Survey on Trustworthy AI in Fintech
    31
    stories filed
    Open issue →
  10. 22
    Vol. 2026
    Back Issue25 – 31 May 2026

    Investigating unauthorized access to GitHub-owned repositories

    • The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
    • [NEU] [hoch] Splunk Splunk Enterprise: Mehrere Schwachstellen
    33
    stories filed
    Open issue →
  11. 21
    Vol. 2026
    Back Issue18 – 24 May 2026

    Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

    • Who Owns This Agent? Tracing AI Agents Back to Their Owners
    • Compositional Jailbreaking: An Empirical Analysis of Mutator Chain Interactions in Aligned LLMs
    63
    stories filed
    Open issue →
  12. 20
    Vol. 2026
    Back Issue11 – 17 May 2026

    Europe is scaling back GDPR and relaxing AI laws

    • Top 10 web hacking techniques of 2024
    • Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'
    35
    stories filed
    Open issue →
  13. 19
    Vol. 2026
    Back Issue4 – 10 May 2026

    Linux-Lücke „Copy Fail“ wird bereits angegriffen

    • [NEU] [UNGEPATCHT] [hoch] Microsoft Windows RPC: Schwachstelle ermöglicht Privilegieneskalation
    • [UPDATE] [kritisch] GNU libc: Mehrere Schwachstellen
    20
    stories filed
    Open issue →
  14. 18
    Vol. 2026
    Back Issue27 April – 3 May 2026

    Two new critical Spinnaker vulns allow RCE and production access

    • What Anthropic’s Mythos Means for the Future of Cybersecurity
    • ChaosDB: How we hacked thousands of Azure customers’ databases
    62
    stories filed
    Open issue →
  15. 15
    Vol. 2026
    Back Issue6 – 12 April 2026

    AI voice cloning used in $4.3M CEO fraud scheme targeting European banks

    • CVE-2026-21345: Critical RCE in widely-used Java XML parser (CVSS 9.8)
    • Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account
    53
    stories filed
    Open issue →