1. CISA confirmed that a remote code execution vulnerability in Microsoft SharePoint is currently being actively exploited (Reddit).
2. Google and the FBI disrupted the NetNut residential proxy network, cutting off access for approximately 2 million compromised devices (BleepingComputer).
3. A new Linux kernel vulnerability named Bad Epoll tracked as CVE-2026-46242 allows unprivileged users to gain root access on servers and Android devices (The Hacker News).
4. Indian authorities are investigating a data leak at Tata that allegedly exposed sensitive information regarding the Apple iPhone 18 Pro (Reddit).
5. The modular malware framework Avalon has been identified, which facilitates phishing, credential theft, and the deployment of CrownX ransomware (The Hacker News).
6. North Korean threat actors are distributing malicious npm packages that mimic Rollup polyfills to steal developer credentials and secrets (The Hacker News).
7. The threat actor group Armored Likho is targeting government agencies and the power sector in Russia, Brazil, and Kazakhstan using the BusySnake stealer (The Hacker News).
8. Former European Parliament member Stelios Kouloglou was targeted and infected with Pegasus spyware while investigating the use of such tools (The Hacker News).
9. Security researchers disclosed seven unpatched vulnerabilities in the FatFs filesystem library, which is widely used in embedded devices like cameras and industrial controllers (The Hacker News).
10. A new phishing as a service platform called ARToken has been identified as an affiliate of the EvilTokens toolkit used to compromise Microsoft 365 accounts (BleepingComputer).
11. A vulnerability in the Apple Hide My Email feature was reported to expose the real email addresses of users (Reddit).
12. Reports indicate that the United States Department of Homeland Security suffered a data breach (Reddit).
Be First to Comment