#bug


GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Jul 22, 2026 // 22:45

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ […]

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Jul 21, 2026 // 23:34

Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining […]

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

Jul 21, 2026 // 13:16

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. Palo Alto […]

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

Jun 25, 2026 // 16:32

It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open […]

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

Jun 25, 2026 // 15:32

It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open […]

29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests

Jun 22, 2026 // 17:34

A heap over-read in the Squid web proxy can leak another user’s cleartext HTTP request, including any credentials or session tokens it carries, to anyone […]

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Jun 20, 2026 // 13:21

Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites. The vulnerability, tracked as […]

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

Jun 19, 2026 // 23:57

Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. The flaw is tracked as CVE-2026-4020 […]

SimpleHelp bug lets hackers create rogue remote support accounts

Jun 15, 2026 // 23:17

A vulnerability in the SimpleHelp remote management software allows unauthenticated attackers to create privileged technician accounts on servers using the OpenID Connect (OIDC) authentication protocol. […]

phpBB forum fixes auth bypass bug lurking for a decade

Jun 12, 2026 // 21:37

A 10-year-old authentication bypass vulnerability discovered in the phpBB forum software allows an attacker to log in as any user, including administrators. The flaw does […]