1. Check Point patched a critical authentication bypass vulnerability in SmartConsole tracked as CVE-2026-16232 which is currently under active exploitation (The Hacker News).
2. Russian state-sponsored group Laundry Bear is exploiting a zero-click vulnerability in Zimbra Collaboration servers to steal emails and credentials (BleepingComputer).
3. The Clop ransomware gang is conducting a data theft extortion campaign targeting internet-exposed PTC Windchill and FlexPLM instances (BleepingComputer).
4. A new campaign by threat actor UAC-0099 uses a malicious Notepad plugin to compromise Windows systems (The Hacker News).
5. Redis released security updates for seven vulnerabilities including authenticated remote code execution flaws found by AI agents (The Hacker News).
6. NodeBB patched eight high-severity security flaws discovered by AI pentest agents that could expose admin access and private chats (The Hacker News).
7. A nine-year-old race condition in the Linux kernel XFS filesystem tracked as CVE-2026-64600 allows local attackers to gain root privileges (BleepingComputer).
8. The Chaos ransomware group is using a new Rust-based backdoor called msaRAT that routes command and control traffic through headless browser instances (The Hacker News).
9. A sandbox escape vulnerability in Claude Cowork allows attackers to break out of a virtual machine to access files on the host macOS system (The Hacker News).
10. Origin Energy confirmed a data breach that resulted in the unauthorized access and exposure of sensitive customer personally identifiable information (BleepingComputer).
11. A malvertising campaign on Bing is distributing the SectopRAT malware via a fake Claude desktop application installer (BleepingComputer).
12. A China-nexus threat cluster identified as JadeProx is using a new Windows loader called TriBack to target government and healthcare organizations (The Hacker News).
13. Attackers are weaponizing compromised GitHub Actions runners to distribute malicious packages targeting cPanel and WHM servers (The Hacker News).
14. A new remote access trojan called Dolphin X utilizes AI-powered profiling to rank and identify high-value targets for infection (BleepingComputer).
15. Swiss train manufacturer Stadler Rail rejected a 12 million dollar ransom demand from the Everest ransomware group following a data theft incident (The Record).
Be First to Comment