blog
News from the world of cyber security
We share our know-how. We advise which cyber security topics need to be addressed and how to proceed. And in the hacking stories section we bring real stories of attacks on Czech companies.
We share our know-how. We advise which cyber security topics need to be addressed and how to proceed. And in the hacking stories section we bring real stories of attacks on Czech companies.
The Coldcard hardware wallet lost roughly 88.6 million dollars to a weak random number generator baked into 2021 firmware, ShinyHunters added more victims with Salesforce-linked data (Questel, Alcon, Lumenis), Adobe Campaign Classic got a patch for a CVSS 10.0 flaw, Rails fixed a critical Active Storage hole, and the CornFlake trojan spread over hijacked hotel Wi-Fi.
Cyber week 2026-W30: AI attacks on its own (the Hermes agent hit Thailand's Finance Ministry, first autonomous ransomware), a Zimbra zero-click (CVE-2025-66376) steals mail and 2FA codes, Clop hits PTC Windchill and FlexPLM, Certighost hands an AD user the domain keys, hotel Wi-Fi DNS gets hijacked.
Cyber week 2026-W29 in brief: a critical RCE in WordPress core (wp2shell, CVE-2026-63030), SonicWall SMA zero-days weaponized by Inc ransomware, the NadMesh botnet hunting exposed AI services and 3,811 AWS keys, ACR Stealer stealing M365 tokens via ClickFix, and Qilin with 32 victims.
Weekly cybersecurity recap (Jul 13-20, 2026) on one theme: today's attacks arrive through trust. D1R used a Synopsys leak to reach Bosch and ARM, ShinyHunters spent a year in Salesforce via OAuth, 148 npm packages ran a DDoS botnet, plus the MemGhost AI attack and three Czech Titan victims.
Sign up for our newsletter and never miss any of our events again! We'll keep you up to date on upcoming event dates, recording release availability, and other news from the Cyber Rangers!