1. Cisco Secure Firewall Management Center is under active exploitation via a zero day vulnerability tracked as CVE 2026 20316 which allows unauthenticated remote access (The Hacker News). 2. Russian state sponsored threat actors are exploiting a zero day vulnerability in Microsoft Outlook Web Access to maintain long term mailbox access via a backdoor named OWAReaper (The Hacker News, BleepingComputer). 3. A coordinated cyberattack targeted…
Posts tagged as “exploit”
1. Check Point patched a critical authentication bypass vulnerability in SmartConsole tracked as CVE-2026-16232 which is currently under active exploitation (The Hacker News). 2. Russian state-sponsored group Laundry Bear is exploiting a zero-click vulnerability in Zimbra Collaboration servers to steal emails and credentials (BleepingComputer). 3. The Clop ransomware gang is conducting a data theft extortion campaign targeting internet-exposed PTC Windchill and FlexPLM instances (BleepingComputer). 4.…
1. Ukraine: Russian forces struck a fuel facility in Zhytomyr on July 23, while Zaporizhzhia was hit by five guided aerial bombs, injuring nearly 20 people. Source: UNIAN. 2. Ukraine: Mykhailo Fedorov stated on July 23 that he will accept no government role other than Minister of Defense following his dismissal. Source: UNIAN. 3. Ukraine: A Russian Su-57 stealth fighter crashed in the Moscow region…
1. Microsoft SharePoint vulnerability CVE-2026-50522 is under active exploitation to steal machine keys and maintain persistent access (The Hacker News). 2. Qilin ransomware actors are actively exploiting the Palo Alto Networks PAN-OS authentication bypass flaw CVE-2026-0257 for initial network access (The Hacker News). 3. Critical vulnerabilities in WordPress Core known as wp2shell are being exploited to install persistent webshells and malicious plugins (Bleeping Computer). 4.…
1. A critical remote code execution vulnerability in the ServiceNow AI Platform identified as CVE-2026-6875 is currently being exploited in the wild (BleepingComputer). 2. The Hugging Face AI model repository suffered a data breach after an autonomous AI agent gained unauthorized access to internal datasets and credentials (The Hacker News). 3. WordPress core vulnerabilities collectively known as wp2shell are being actively exploited to achieve remote…
1. Microsoft released a record 622 patches for its July Patch Tuesday, including two zero-day vulnerabilities currently under active exploitation (The Hacker News). 2. CISA issued a warning regarding three actively exploited vulnerabilities in internet-exposed on-premises SharePoint Server instances (Bleeping Computer). 3. SonicWall confirmed active exploitation of two zero-day vulnerabilities in its SMA 1000 series appliances, including one allowing arbitrary command execution (The Hacker News).…
1. The jscrambler npm package release 8.14.0 was compromised to drop and execute a malicious Rust infostealer on Windows, macOS, and Linux systems (https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html). 2. Suspected China and India aligned threat actors conducted sustained cyber espionage campaigns against the Balochistan Police portal between February 2024 and April 2026 (https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html). 3. Progress Software urged ShareFile customers to shut down Storage Zone Controllers due to a credible…
1. Attackers are exploiting the Ill Bloom vulnerability in cryptocurrency wallet software to drain funds by predicting recovery phrases generated with weak randomness (thehackernews.com). 2. A former ransomware negotiator was sentenced to 70 months in prison for conspiring with the BlackCat ransomware group to extort victims (thehackernews.com). 3. The new GodDamn ransomware family is using the PoisonX kernel driver to disable endpoint security software (thehackernews.com).…
1. CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog including a critical path traversal flaw in Adobe ColdFusion. (thehackernews.com) 2. Federal agencies were ordered by CISA to prioritize patching an actively exploited authentication bypass vulnerability in the Langflow AI framework. (bleepingcomputer.com) 3. Researchers disclosed GhostLock CVE-2026-43499 a 15-year-old Linux kernel flaw that allows unprivileged users to gain root access and escape…
1. CISA issued a warning regarding the active exploitation of a Linux kernel zero day vulnerability identified as CVE 2026 43456 (reddit.com). 2. Researchers discovered the TrojPix attack which exfiltrates data from air gapped systems by manipulating screen pixels to radiate radio signals via video cables (thehackernews.com). 3. A new Java based remote access trojan named QuimaRAT is being distributed under a malware as a…
1. CISA added the critical SharePoint remote code execution vulnerability CVE-2026-45659 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News). 2. Security researchers identified the first end-to-end ransomware attack executed by an AI agent, which exploited a Langflow remote code execution flaw to encrypt a production database (The Hacker News). 3. The FortiBleed campaign, which compromised 75000 Fortinet firewalls, has…
1. Attackers are actively exploiting a critical vulnerability in Cisco Unified CM and Unified CM SME deployments that enables server side request forgery and privilege escalation to root (Dark Reading). 2. A critical code injection vulnerability in Lantronix EDS5000 series devices tracked as CVE 2025 67038 is being actively exploited in the wild (The Hacker News). 3. Threat actors exploited the Cisco Catalyst SD WAN…
1. Threat actors are actively exploiting a critical vulnerability in Cisco Unified Communications Manager tracked as CVE-2026-20230 to achieve remote file writes (thehackernews.com). 2. The FortiBleed campaign has targeted over 430,000 FortiGate firewalls globally to harvest approximately 110 million credentials (thehackernews.com). 3. Two members of the Scattered Spider cybercrime group pleaded guilty to charges related to the 2024 cyberattack on Transport for London (bleepingcomputer.com). 4.…
1. The Canadian Security Intelligence Service utilized a first of its kind threat reduction warrant to neutralize two foreign run botnets by accessing infected servers and routers on Canadian soil (The Hacker News). 2. A new malware family identified as AryStinger has compromised at least 4300 legacy routers to establish a distributed reconnaissance and proxy network (The Hacker News). 3. Researchers report that AryStinger is…
1. CISA added a critical Splunk Enterprise remote code execution vulnerability CVE-2026-20253 to its known exploited vulnerabilities catalog after reports of active exploitation (https://www.reddit.com/r/cybersecurity/comments/1ua3npz/cisa_adds_splunk_enterprise_rce_cve202620253_to/). 2. International law enforcement agencies disrupted the SocGholish botnet infrastructure and cleaned nearly 15000 infected WordPress sites in an operation linked to the Evil Corp cybercrime group (https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html). 3. CISA issued a warning regarding the FortiBleed campaign which has compromised over…
1. CISA has issued an urgent directive for federal agencies to patch a maximum severity vulnerability in the Widget Factory Joomla Content Editor plugin, which is currently being exploited in the wild (The Hacker News). 2. Microsoft is developing a patch for a zero day privilege escalation vulnerability in the Defender Malware Protection Engine codenamed RoguePlanet (The Hacker News). 3. Threat actors are actively exploiting…
1. Cisco released security updates for a vulnerability in Catalyst SD-WAN Manager tracked as CVE-2026-20262 which is currently being exploited in the wild (thehackernews.com). 2. CISA added the LiteSpeed cPanel Plugin vulnerability CVE-2026-54420 to its Known Exploited Vulnerabilities catalog due to active exploitation for root privilege escalation (thehackernews.com). 3. Threat actors are actively exploiting multiple critical vulnerabilities in the Fortinet FortiSandbox platform to compromise systems…
1. Splunk Enterprise is affected by a critical unauthenticated remote code execution vulnerability tracked as CVE-2026-20253 (The Hacker News). 2. The ShinyHunters threat group is actively exploiting a zero day vulnerability in Oracle PeopleSoft to compromise hundreds of organizations (Reddit). 3. CISA has issued an emergency directive requiring federal agencies to patch a maximum severity Ivanti vulnerability within three days (Reddit). 4. The Lapsus ransomware…
1. CISA issued a binding operational directive requiring federal agencies to patch an actively exploited vulnerability in Ivanti Sentry within three days (bleepingcomputer.com). 2. The ShinyHunters extortion group is actively exploiting a critical remote code execution vulnerability in Oracle PeopleSoft tracked as CVE-2026-35273 (thehackernews.com). 3. Researchers identified a critical vulnerability chain in the LangGraph AI framework that allows for remote code execution via SQL injection…
1. Microsoft released a record number of security patches for June 2026 including fixes for YellowKey and GreenPlasma zero day vulnerabilities (https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-yellowkey-greenplasma-miniplasma-zero-days/) 2. A new Microsoft Defender zero day exploit named RoguePlanet was released by a researcher granting SYSTEM privileges on updated Windows systems (https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/) 3. ServiceNow confirmed that threat actors exploited a flaw to gain unauthorized access to customer instances (https://thehackernews.com/2026/06/servicenow-flaw-exploited-to-gain.html) 4. Ivanti patched…
1. Miasma malware has impacted 73 Microsoft GitHub repositories leading to security concerns regarding repository integrity (Reddit). 2. Threat actor UNC3753 is conducting a financially motivated data theft and extortion campaign against U.S. professional and financial services (The Hacker News). 3. Over 20000 Instagram accounts were hijacked after attackers abused Meta AI support systems to reset user passwords (Bleeping Computer). 4. Hackers are actively exploiting…
1. CISA added the critical Magento RCE vulnerability CVE-2026-45247 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News). 2. A large scale malvertising campaign is using fake websites mimicking open source tools to distribute malware families like Remus Stealer and SessionGate (The Hacker News). 3. Attackers successfully compromised a senior executive at a global stock exchange, maintaining access to their…
1. Palo Alto Networks confirmed that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, is under active exploitation in the wild. (The Hacker News) 2. Attackers are actively exploiting the GlobalProtect authentication bypass flaw to establish unauthorized VPN connections to corporate networks. (BleepingComputer) 3. A new local privilege escalation vulnerability named CIFSwitch has been identified in the Linux kernel, allowing attackers to gain root access…
1. Palo Alto Networks confirmed that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS and Prisma Access, is currently under active exploitation (thehackernews.com). 2. Dutch authorities successfully dismantled a massive botnet consisting of 17 million infected devices and seized over 200 associated servers (bleepingcomputer.com). 3. A Russian-linked threat actor named GREYVIBE has been identified conducting persistent AI-powered cyberattacks against Ukrainian entities since August 2025 (thehackernews.com). 4.…
1. A critical SQL injection vulnerability in Drupal Core tracked as CVE-2026-9082 is being actively exploited with over 15000 attempts recorded across 6000 sites (The Hacker News). 2. The LiteSpeed User-End cPanel Plugin is under active exploitation via CVE-2026-48172 which allows attackers to execute arbitrary scripts with root privileges (The Hacker News). 3. The Megalodon campaign compromised over 5500 GitHub repositories within six hours by…
1. Microsoft confirmed active exploitation of two Microsoft Defender vulnerabilities including CVE-2026-41091 which grants SYSTEM privileges (The Hacker News). 2. CISA added critical vulnerabilities in Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities catalog following evidence of active use (The Hacker News). 3. Cisco patched a maximum severity vulnerability CVE-2026-20223 in Secure Workload that allows unauthenticated remote attackers to access sensitive data…
1. GitHub is investigating a breach of approximately 3800 internal repositories after an employee installed a malicious VS Code extension (The Hacker News). 2. Microsoft released a mitigation for the YellowKey BitLocker bypass vulnerability tracked as CVE-2026-45585 (The Hacker News). 3. Grafana Labs confirmed a breach of its internal GitHub environment involving source code, though customer production systems remain unaffected (The Hacker News). 4. The…
1. A critical heap buffer overflow vulnerability in NGINX tracked as CVE-2026-42945 is being actively exploited in the wild to cause worker crashes and potential remote code execution (The Hacker News). 2. Security researcher Chaotic Eclipse released a proof of concept for a Windows zero day exploit named MiniPlasma that grants attackers SYSTEM privileges on fully patched systems (Bleeping Computer). 3. The Tycoon2FA phishing kit…
1. Microsoft Exchange and Windows 11 were successfully compromised by researchers using zero day vulnerabilities during the Pwn2Own Berlin 2026 event (bleepingcomputer.com). 2. The Funnel Builder WordPress plugin is being actively exploited to inject malicious JavaScript into WooCommerce checkout pages to steal credit card data (bleepingcomputer.com). 3. A critical supply chain attack targeting the TanStack library impacted two OpenAI employee devices, prompting immediate security containment…
1. A new Linux kernel local privilege escalation vulnerability named Fragnesia tracked as CVE-2026-46300 allows attackers to gain root access (The Hacker News). 2. A critical heap buffer overflow vulnerability in the NGINX rewrite module tracked as CVE-2026-42945 enables unauthenticated remote code execution (The Hacker News). 3. West Pharmaceutical Services confirmed a cyberattack involving data exfiltration and system encryption (BleepingComputer). 4. The Gentlemen ransomware group…
1. A mass npm supply chain attack involving the Mini Shai-Hulud worm has compromised over 170 packages including TanStack and Mistral AI. (https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html) 2. Instructure reached an agreement with the ShinyHunters extortion group to prevent the leak of 3.65TB of stolen data. (https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html) 3. A rogue version of the official Checkmarx Jenkins plugin was published on the Jenkins Marketplace containing an infostealer. (https://www.bleepingcomputer.com/news/security/official-checkmarx-jenkins-package-compromised-with-infostealer/) 4. A…
1. The ShinyHunters threat group claims to have stolen 275 million records from Canvas LMS affecting 9000 schools with a ransom deadline set for May 12 (Reddit). 2. Instructure reported a second security incident involving its Canvas platform following the massive data breach (Reddit). 3. The official JDownloader website was compromised to distribute malicious installers containing a Python based remote access trojan (BleepingComputer). 4. A…
1. Microsoft confirmed active exploitation of the Windows Shell spoofing vulnerability CVE 2026 32202 (The Hacker News). 2. A Chinese national linked to the Silk Typhoon threat group was extradited to the United States for cyberattacks against government agencies (The Hacker News). 3. French authorities arrested a 21 year old hacker known as HexDex for approximately 100 data breaches including the French Ministry of National…
1. CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog affecting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X routers (The Hacker News). 2. Home security company ADT confirmed a data breach following extortion threats from the ShinyHunters group (BleepingComputer). 3. The Lazarus APT group is conducting a new campaign using the Mach-O Man malware kit to target businesses on macOS (Reddit).…
1. Region: Ukraine. Ukraine launched a massive drone and cruise missile strike against Crimea and Russia, with reports of over 250-270 projectiles airborne. Source: Obserwator Wojen. 2. Region: Middle East. Iranian Foreign Minister Abbas Araghchi arrived in Islamabad for talks on regional stability, though Iran denied plans for direct negotiations with US envoys Jared Kushner and Steve Witkoff. Source: Reuters. 3. Region: Middle East. The…
1. A high severity SSRF vulnerability in LMDeploy tracked as CVE 2026 33626 is being actively exploited in the wild within 13 hours of its disclosure (thehackernews.com). 2. The Bitwarden CLI npm package was compromised as part of an ongoing supply chain attack involving malicious code in the bw1.js file (thehackernews.com). 3. The threat group UNC6692 is conducting a campaign by impersonating IT helpdesk staff…
1. Over 1300 Microsoft SharePoint servers remain vulnerable to a spoofing zero day exploit that is currently being used in active attacks (BleepingComputer). 2. Microsoft released emergency out of band security updates to address a critical privilege escalation vulnerability in ASP.NET Core (BleepingComputer). 3. CISA has flagged a new SD WAN vulnerability that is currently being exploited in the wild (Reddit). 4. Researchers discovered a…
1. Cloud development platform Vercel confirmed a security breach involving unauthorized access to internal systems following the compromise of a third party AI tool used by an employee (The Hacker News). 2. Threat actors are actively exploiting a 17 year old Microsoft Excel vulnerability which has been flagged by the US cyber defense agency (Reddit). 3. Researchers identified a new malware strain named ZionSiphon targeting…
1. Three Microsoft Defender zero day vulnerabilities codenamed BlueHammer RedSun and UnDefend are being actively exploited in the wild to gain elevated privileges (The Hacker News). 2. The Payouts King ransomware group is utilizing QEMU virtual machines as a reverse SSH backdoor to evade detection by endpoint security solutions (BleepingComputer). 3. The Grinex cryptocurrency exchange has suspended operations following a 13.7 million dollar hack that…
1. Ukraine: Russian forces launched a massive aerial assault involving 172 drones and an Iskander-M missile, resulting in 18 fatalities and over 100 injuries across multiple cities. Source: WorldWideWatchers. 2. Ukraine: A Ukrainian soldier successfully downed a Russian kamikaze drone using a Yak-52 training aircraft. Source: Neferolan. 3. Ukraine: Ukrainian drones struck the Rosneft oil terminal in Tuapse, Russia, causing a significant fire. Source: Neferolan.…
1. A cluster of 108 malicious Google Chrome extensions was identified stealing user data and Telegram information from approximately 20000 users (thehackernews.com). 2. The critical ShowDoc remote code execution vulnerability CVE-2025-0520 is currently being actively exploited in the wild (thehackernews.com). 3. CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog including a critical SQL injection flaw in Fortinet FortiClient EMS tracked as CVE-2026-21643 (thehackernews.com).…
1. Adobe released an emergency patch for CVE-2026-34621, a critical vulnerability in Acrobat Reader currently under active exploitation in the wild (The Hacker News). 2. Threat actors compromised the CPUID website to distribute trojanized versions of CPU-Z and HWMonitor, which deployed the STX RAT to unsuspecting users (The Hacker News). 3. ShinyHunters claimed a data breach affecting Rockstar Games, allegedly facilitated through a Snowflake integration…
1. A remote unauthenticated RCE to root chain vulnerability has been identified in CUPS (https://www.reddit.com/r/netsec/comments/1sflk3t/spooler_alert_remote_unauthd_rcetoroot_chain_in/). 2. A path traversal vulnerability in an MCP server allows AI agents to access sensitive SSH keys (https://www.reddit.com/r/netsec/comments/1sfhmaa/we_found_a_path_traversal_in_an_mcp_server_with/). 3. A self propagating credential worm has compromised npm packages under the fairwords scope to steal tokens and infect PyPI packages (https://www.reddit.com/r/Malware/comments/1sfjg9f/fairwords_npm_packages_compromised_by_a/). 4. Authorities have disrupted a campaign involving router DNS hijacks…
1. Fortinet released an emergency patch for a critical vulnerability in FortiClient EMS that is currently being exploited in the wild (BleepingComputer). 2. German authorities identified a 31 year old Russian national as the leader of the REvil and GandCrab ransomware gangs responsible for over 130 attacks (The Hacker News). 3. A six month social engineering campaign by DPRK threat actors resulted in the theft…
1. ShinyHunters compromised Cisco source code and AWS keys by exploiting a supply chain vulnerability in Trivy. The breach resulted in the unauthorized cloning of over 300 repositories (https://www.reddit.com/r/netsec/comments/1sa8nld/cisco_source_code_stolen_by_shinyhunters_via/). 2. Google released a patch for a high severity Chrome zero day vulnerability identified as CVE 2026 5281 which is currently under active exploitation (https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html). 3. Apple expanded the availability of iOS 18.7.7 and iPadOS 18.7.7…
1. A critical vulnerability in Fortinet FortiClient EMS is currently being exploited in active attacks. (bleepingcomputer.com) 2. The European Commission confirmed a data breach following a cyberattack on the Europa.eu platform claimed by the ShinyHunters extortion gang. (bleepingcomputer.com) 3. Pro-Iran hacktivist group Handala breached the personal email account of FBI Director Kash Patel and published sensitive documents. (bleepingcomputer.com) 4. Three China-linked threat clusters are targeting…
1. Citrix NetScaler ADC and Gateway are under active reconnaissance for CVE-2026-3055, a critical memory overread vulnerability with a CVSS score of 9.3 (The Hacker News). 2. CISA added CVE-2025-53521, a critical remote code execution flaw in F5 BIG-IP Access Policy Manager, to its Known Exploited Vulnerabilities catalog (The Hacker News). 3. Russian state-sponsored group TA446 is deploying the DarkSword iOS exploit kit in targeted…