1. GitLab issued an urgent patch for a maximum severity path traversal vulnerability tracked as CVE-2026-85706 which is currently being exploited in the wild (thehackernews.com). 2. Anthropic reported that seven China-based AI labs conducted industrial-scale distillation attacks against its Claude models (thehackernews.com). 3. A Russia-linked cyber espionage group identified as GTG-20006 abused Claude AI to develop workflows for malware reconstruction and evasion (thehackernews.com). 4. Threat…
Posts tagged as “CVE”
1. Adobe released patches for a critical zero day vulnerability in Magento and Adobe Commerce tracked as CVE 2026 75650 which is being actively exploited to deploy backdoors (thehackernews.com). 2. A Vietnam linked database leak exposed 220 million traveler and crew records including passport numbers and flight details via a cloud path using default credentials (bleepingcomputer.com). 3. The BigBear 2.0 phishing as a service framework…
1. Attackers are actively exploiting MikroTik routers by targeting internet exposed SSH services to gain full administrative control without authentication (The Hacker News). 2. A new unpatched zero day vulnerability in Magento and Adobe Commerce dubbed StyleSmuggler is being exploited to inject malicious code into online stores (The Hacker News). 3. JetBrains confirmed that threat actors exploited a critical vulnerability in TeamCity to breach its…
1. Google released a security update to patch CVE-2026-85046, a high-severity type confusion vulnerability in the V8 engine that is currently being exploited in the wild (The Hacker News). 2. Over 440,000 exploit attempts have been recorded targeting critical remote code execution flaws in WordPress plugins Super Forms and Elementor Pro (The Hacker News). 3. Cisco issued patches for a critical vulnerability in Nexus 9000…
1. TerminalFix campaigns are using fake Cloudflare CAPTCHAs to trick users into executing malicious commands via Windows Terminal or PowerShell (thehackernews.com). 2. The ShinyHunters extortion group claims to have stolen 284 million patient records from McKesson following a voice phishing attack (bleepingcomputer.com). 3. Berlin state government officials confirmed a data breach and stated they will not pay the ransom demanded by the hackers (thehackernews.com). 4.…
1. GitLab vulnerability CVE-2026-19478 is under active exploitation allowing unauthenticated attackers to modify or delete projects (The Hacker News). 2. Microsoft confirmed active exploitation of a maximum severity remote code execution flaw in Entra ID tracked as CVE-2026-69836 (Bleeping Computer). 3. CISA ordered federal agencies to patch two actively exploited vulnerabilities affecting the TrueConf Server platform (Bleeping Computer). 4. A critical command injection vulnerability in…
1. Lazarus Group exploited a Windows zero day vulnerability to deploy backdoors against defense and aerospace firms in a campaign known as Operation Dream Job (bleepingcomputer.com). 2. Threat actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint identified as CVE 2026 55040 following the release of proof of concept code (thehackernews.com). 3. A critical remote code execution flaw in VMware vCenter Server…
1. Threat actors are actively exploiting a critical directory traversal vulnerability in VMware vCenter tracked as CVE-2026-59310 to gain persistent remote access (thehackernews.com). 2. CISA confirmed that ransomware groups are actively abusing a high severity remote code execution vulnerability in Microsoft SharePoint tracked as CVE-2026-55040 (bleepingcomputer.com). 3. Cisco reported that CVE-2026-20349, a high severity flaw in ASA and FTD software, is being exploited in the…
1. A critical zero day vulnerability in Metabase software is being actively exploited in the wild to allow unauthenticated remote attackers to inject arbitrary SQL and gain administrative access (The Hacker News). 2. CISA added a critical command injection flaw in Progress Kemp LoadMaster tracked as CVE 2026 8037 to its Known Exploited Vulnerabilities catalog following active exploitation reports (The Hacker News). 3. A new…
1. CISA added the high severity authentication bypass vulnerability CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed (The Hacker News). 2. INC Ransomware is identified as the primary threat actor exploiting security flaws in SonicWall SMA 1000 series VPN appliances (The Hacker News). 3. Microsoft linked a global campaign targeting hospitality Wi-Fi networks to the Russian state-sponsored actor…