1. Cisco Secure Firewall Management Center is under active exploitation via a zero day vulnerability tracked as CVE 2026 20316 which allows unauthenticated remote access (The Hacker News).
2. Russian state sponsored threat actors are exploiting a zero day vulnerability in Microsoft Outlook Web Access to maintain long term mailbox access via a backdoor named OWAReaper (The Hacker News, BleepingComputer).
3. A coordinated cyberattack targeted operational technology at over 30 Minnesota water systems causing plant outages and communication failures (The Hacker News).
4. A critical vulnerability in Ruby on Rails tracked as CVE 2026 66066 allows unauthenticated attackers to read arbitrary server files through malicious image uploads (The Hacker News).
5. Researchers identified a maximum severity vulnerability in the Ruflo agent meta harness tracked as CVE 2026 59726 that enables unauthenticated remote code execution (The Hacker News).
6. Broadcom issued security updates for critical flaws in VMware products including authentication bypass and virtual machine escape vulnerabilities (The Hacker News).
7. The UK Department for Education suffered a data breach resulting in the leak of over 600000 records belonging to head teachers and government officials (Reddit).
8. Amazon attributed the September 2025 hijacking of npm packages debug and chalk to the North Korean threat group Sapphire Sleet (The Hacker News).
9. Hugging Face experienced a security incident where a malicious dataset was used to execute code on servers and capture internal credentials (Schneier).
10. A long standing vulnerability in Microsoft Secure Boot has been identified by ESET researchers as being exploitable for over a decade (Schneier).
11. A nine year fraud campaign involving cloned websites of major Russian companies has been uncovered targeting international firms for advance payments (The Hacker News).
12. Google Chrome version 151 was released to address 370 security vulnerabilities (Reddit).
13. The FCC added foreign produced mobile robots and networked power inverters to its covered list to mitigate potential cybersecurity risks (The Hacker News).
14. North Korean hackers are increasingly targeting their own government while continuing to conduct global cryptocurrency theft (Bitdefender).
15. Cloudflare has implemented support for post quantum authentication for connections to customer origin servers (Cloudflare).
Be First to Comment