1. Arista VeloCloud Orchestrator on-premise versions are under active exploitation due to a critical command injection vulnerability tracked as CVE-2026-16812 (thehackernews.com).
2. JetBrains issued a critical security update for TeamCity On-Premises to address CVE-2026-63077, which allows for unauthenticated arbitrary code execution (thehackernews.com).
3. Hackers are actively exploiting a zero-day vulnerability in the FastJson Java library to achieve remote code execution on US firm servers (bleepingcomputer.com).
4. A public exploit has been released for a pre-authentication code execution flaw in vBulletin versions 6.2.1 and earlier (thehackernews.com).
5. The Dysphoria IoT botnet has expanded to 200,000 devices and adopted blockchain-based command and control infrastructure to resist disruption (bleepingcomputer.com).
6. A medical billing firm named MCBS disclosed a data breach from 2025 that exposed the sensitive information of 1.26 million individuals (bleepingcomputer.com).
7. The ShinyHunters extortion gang claimed responsibility for a data breach at Ernst and Young involving stolen system credentials (bleepingcomputer.com).
8. The Coca-Cola Company confirmed that hackers stole data from its dairy subsidiary Fairlife during a recent ransomware attack (bleepingcomputer.com).
9. An autonomous AI agent was used in a cyber-espionage campaign targeting the Ministry of Finance in Thailand (therecord.media).
10. A Microsoft Teams-themed phishing campaign dubbed Operation BlueDash is delivering remote monitoring tools to victims via counterfeit update pages (thehackernews.com).
11. Researchers identified a Linux kernel exploit, CVE-2026-53264, which was developed with the assistance of artificial intelligence to elevate local users to root privileges (thehackernews.com).
12. AnMed health system in South Carolina and Georgia closed offices following a malware attack that disrupted its network operations (therecord.media).
13. A proof-of-concept exploit for the Certighost vulnerability in Windows Active Directory Certificate Services has been released, enabling potential domain hijacking (bleepingcomputer.com).
14. The n8n automation platform patched a high-severity sandbox escape vulnerability that allowed authenticated users to execute operating system commands (thehackernews.com).
15. Nichirei, a Japanese logistics and food supplier, suffered a ransomware attack that resulted in personal data theft and shipping disruptions (research.checkpoint.com).
Be First to Comment