1. GitLab vulnerability CVE-2026-19478 is under active exploitation allowing unauthenticated attackers to modify or delete projects (The Hacker News).
2. Microsoft confirmed active exploitation of a maximum severity remote code execution flaw in Entra ID tracked as CVE-2026-69836 (Bleeping Computer).
3. CISA ordered federal agencies to patch two actively exploited vulnerabilities affecting the TrueConf Server platform (Bleeping Computer).
4. A critical command injection vulnerability in Zimbra Collaboration tracked as CVE-2026-73570 is being actively exploited in the wild (The Hacker News).
5. Fourteen trojanized npm packages were discovered distributing a new Linux backdoor named RedC2 4.0 (The Hacker News).
6. Malicious actors compromised a Rust maintainer account to inject build-time malware into widely used crates including arrayref and internment (The Hacker News).
7. A new malware family called SynkLoader is being distributed via Microsoft Teams phishing campaigns to steal user credentials (Bleeping Computer).
8. Researchers identified a new Android malware family targeting vehicle head unit firmware to facilitate ad fraud and proxy botnet operations (The Hacker News).
9. The Hospital for Sick Children in Toronto reported a data breach involving employee and applicant information caused by a third-party software flaw (Bleeping Computer).
10. A campaign involving 40 malicious Firefox extensions masquerading as Web3 products is actively stealing cryptocurrency wallet secrets (The Hacker News).
11. Threat actors are abusing FTP server banners to deliver two previously undocumented remote access trojans named E4del and PINHOLE (Bleeping Computer).
12. Three Russian cyber espionage clusters are leveraging legitimate Google OAuth and WhatsApp flows to target individuals in government and aerospace sectors (The Hacker News).
13. U.S. authorities warned of an active threat where AI-generated scripts are used to target Siemens S7 programmable logic controllers in critical infrastructure (The Hacker News).
14. A critical authentication bypass vulnerability was disclosed in Citrix NetScaler ADC and NetScaler Gateway (The Hacker News).
15. Over 9300 AWS access keys exposed between 2022 and 2026 remain active and pose a risk of unauthorized corporate account access (Bleeping Computer).
Be First to Comment