July 2, 2026
- Synacktiv disclosed an unauthenticated RCE in Argo CD's repo-server enabling full Kubernetes cluster takeover via malicious manifests and Redis cache abuse — reachable by anyone who can hit the internal port. There is no fix and no CVE yet; the write-up includes the CodeQL analysis used to find it. Synacktiv, The Hacker News. · Vulnerabilities & Exploits
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US