1. A critical zero day vulnerability in Metabase software is being actively exploited in the wild to allow unauthenticated remote attackers to inject arbitrary SQL and gain administrative access (The Hacker News).
2. CISA added a critical command injection flaw in Progress Kemp LoadMaster tracked as CVE 2026 8037 to its Known Exploited Vulnerabilities catalog following active exploitation reports (The Hacker News).
3. A new campaign has published nearly 800 malicious npm packages designed to deliver cross platform remote access trojans and infostealers to Windows Mac and Linux systems (The Hacker News).
4. Threat actor group UNC6671 is conducting vishing attacks against enterprise employees to steal sensitive SaaS data by posing as IT help desk staff (The Hacker News).
5. A widespread phishing campaign using adversary in the middle techniques is targeting Microsoft 365 accounts to hijack sessions and collect financial or payroll emails (The Hacker News).
6. Researchers discovered a pre authentication reflected cross site scripting vulnerability in WordPress tracked as CVE 2026 64638 that can be chained to achieve remote code execution (The Hacker News).
7. A critical 18 year old use after free vulnerability in Linux SCTP networking code allows local users to gain root privileges and escape containers (The Hacker News).
8. Atlassian Rovo AI assistant can be manipulated via malicious instructions to collect and exfiltrate internal Jira and Confluence data to external servers (The Hacker News).
9. New CSS based attack techniques can bypass webmail defenses in services like Outlook and Gmail to steal passwords and session tokens (The Hacker News).
10. ClickFix style attacks are being used to deliver macOS malware capable of stealing cryptocurrency wallets and browser stored credentials (The Hacker News).
11. N able released emergency hotfixes for its N central RMM product to address ongoing exploitation of a recently disclosed security flaw (The Hacker News).
12. Healthcare software company Unlimited Technology Systems disclosed a data breach impacting 3.8 million people (Bleeping Computer).
13. Levi Strauss and Co confirmed that hackers stole corporate data after using social engineering to compromise employee machines (Bleeping Computer).
14. The North Carolina Ports Authority confirmed a cyberattack that disrupted IT operations at multiple port facilities (Bleeping Computer).
15. IEH Corporation reported a cyber incident involving its systems used for military satellite and missile production (The Record).
16. TeamPCP threat actors were linked to long standing attacks against Redis infrastructure and supply chain campaigns dating back to 2020 (The Hacker News).
Be First to Comment