1. Threat actors are actively exploiting a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition tracked as CVE-2026-9586 to deploy reverse shells (thehackernews.com).
2. A critical authentication bypass vulnerability in JFrog Artifactory, CVE-2026-82329, is being actively exploited to mint administrative tokens shortly after its disclosure (thehackernews.com).
3. Attackers are exploiting a critical remote code execution flaw in the Langflow AI framework, CVE-2026-0768, to steal sensitive OpenAI and AWS credentials (bleepingcomputer.com).
4. SonicWall has issued a warning regarding two actively exploited zero-day vulnerabilities in its SMA1000 series appliances that allow for remote code execution (bleepingcomputer.com).
5. International law enforcement agencies successfully dismantled the infrastructure of the long-standing Sality peer-to-peer botnet (thehackernews.com).
6. A Russian national was extradited to the United States to face charges for a phishing campaign that infected approximately 80,000 freelancers with malware between 2016 and 2017 (thehackernews.com).
7. A dark web service is reportedly selling digital scans of over 153 million driver licenses from the United States and Canada, prompting an FBI investigation (krebsonsecurity.com).
8. Aesto Health disclosed a significant data breach affecting more than 9.5 million patients (bleepingcomputer.com).
9. The threat actor group Breeze Comet is targeting Brazilian financial and retail organizations to manipulate payment systems and conduct fraudulent transfers (thehackernews.com).
10. Researchers identified 13 malicious packages on Packagist that inject JavaScript into streaming sites to target unpatched iOS devices and steal cryptocurrency wallet seeds (thehackernews.com).
11. The Iranian hacking group Nimbus Manticore is using cross-platform remote access trojans developed in Node.js to target aviation and fintech developers (thehackernews.com).
12. Approximately 22,000 Microsoft Exchange servers remain vulnerable to a high-severity authentication bypass flaw that allows attackers to hijack user mailboxes (bleepingcomputer.com).
13. The non-profit organization METR suffered security incidents where attackers stole an API key and consumed approximately 600,000 dollars in AI model credits (thehackernews.com).
14. Threat actors are abusing the legitimate Faronics Deploy endpoint management platform to gain remote administrative control over victim systems (bleepingcomputer.com).
15. Recently patched zero-day vulnerabilities in PaperCut NG and MF software are being actively exploited by attackers to facilitate data theft (bleepingcomputer.com).
Be First to Comment