7-Zip CVE-2026-48095 Fix
CVE-2026-48095 is a 7-Zip NTFS handler heap overflow fixed in 7-Zip 26.01. Update from official sources and treat unexpected archives or renamed files cautiously.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 4, 2026
CVE-2026-48095 is a 7-Zip NTFS handler heap overflow fixed in 7-Zip 26.01. Update from official sources and treat unexpected archives or renamed files cautiously.
A Packagist and GitHub supply-chain campaign used malicious postinstall hooks to fetch Linux malware from GitHub Releases. Check package.json, CI logs, and build tokens.
Laravel-Lang Composer packages were compromised through rewritten tags that run a PHP credential stealer as soon as Composer autoload is loaded.
Grafana says attackers copied two private GitHub repositories after one workflow token was missed during post-TanStack credential rotation.
CERT-UA says Ghostwriter used compromised accounts and fake Prometheus certificate lures to target Ukrainian government entities with OYSTERFRESH malware.
Check Point says Nimbus Manticore used SEO poisoning, fake software lures, and installer abuse to deploy the new MiniFast backdoor during regional conflict activity.
Europol says First VPN, a Russian-speaking cybercrime VPN, was dismantled in Operation Saffron after years of use by ransomware actors and fraud crews.
Langflow CVE-2025-34291 can turn a malicious webpage into account takeover and RCE through CORS, refresh-token handling, and code validation. Check versions, exposure, and session…
Trend Micro patched an Apex One on-prem directory traversal flaw after observing exploitation attempts. CISA added CVE-2026-34926 to KEV.