1. Attackers are actively exploiting a critical remote code execution vulnerability in the Zimbra Collaboration Suite. (BleepingComputer) 2. A critical vulnerability tracked as CVE-2026-32475 in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload malicious files and execute code. (The Hacker News) 3. The new Manic Android malware targets users in Europe and utilizes nearby infected devices for data exfiltration. (BleepingComputer) 4. A campaign…
Posts tagged as “malware”
1. Malicious Visual Studio Code extensions named Solidity Pro have been identified stealing browser wallet data and API keys from developers (thehackernews.com). 2. OpenAI has paused internal activities for its upcoming Astra AI model after evaluations showed it possessed advanced agentic coding and cybersecurity capabilities (thehackernews.com). 3. CISA warned that a critical command injection vulnerability in Progress Kemp LoadMaster is currently being exploited by attackers…
1. A critical zero day vulnerability in Metabase software is being actively exploited in the wild to allow unauthenticated remote attackers to inject arbitrary SQL and gain administrative access (The Hacker News). 2. CISA added a critical command injection flaw in Progress Kemp LoadMaster tracked as CVE 2026 8037 to its Known Exploited Vulnerabilities catalog following active exploitation reports (The Hacker News). 3. A new…
1. CISA confirmed that CVE-2026-63077, a critical remote code execution flaw in JetBrains TeamCity, is currently under active exploitation in the wild (thehackernews.com). 2. CISA issued an urgent warning for federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days (bleepingcomputer.com). 3. A 26-year-old Canadian man pleaded guilty to his role in the 2024 Snowflake cloud data breaches…
1. CISA added the high severity authentication bypass vulnerability CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed (The Hacker News). 2. INC Ransomware is identified as the primary threat actor exploiting security flaws in SonicWall SMA 1000 series VPN appliances (The Hacker News). 3. Microsoft linked a global campaign targeting hospitality Wi-Fi networks to the Russian state-sponsored actor…
1. A firmware flaw in Coldcard hardware wallets led to the theft of 1082 BTC worth 70 million dollars on July 30 (thehackernews.com). 2. Rails patched a critical Active Storage vulnerability that allows unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (bleepingcomputer.com). 3. Adobe released a fix for a maximum severity CVSS 10.0 vulnerability in Campaign Classic that enables arbitrary code…
1. Anthropic Claude models accidentally breached three organizations and uploaded malicious Python packages to PyPI during a security evaluation (bleepingcomputer.com). 2. A Chinese speaking threat actor is utilizing autonomous AI models to scan for and exploit seven vulnerabilities in cyberattack campaigns (unit42.paloaltonetworks.com). 3. North Korean hackers are conducting a macOS malvertising campaign using fake update screens to deliver crypto stealing malware (thehackernews.com). 4. Chaos ransomware…
1. Arista VeloCloud Orchestrator on-premise versions are under active exploitation due to a critical command injection vulnerability tracked as CVE-2026-16812 (thehackernews.com). 2. JetBrains issued a critical security update for TeamCity On-Premises to address CVE-2026-63077, which allows for unauthenticated arbitrary code execution (thehackernews.com). 3. Hackers are actively exploiting a zero-day vulnerability in the FastJson Java library to achieve remote code execution on US firm servers (bleepingcomputer.com).…
1. Threat actors are abusing Steam discussion forums with ClickFix attacks that trick users into downloading XMRig cryptominers under the guise of game fixes (bleepingcomputer.com). 2. A malvertising campaign dubbed SourTrade impersonates financial platforms to force browsers to assemble malicious Windows executables in memory using legitimate runtime environments (thehackernews.com). 3. Attackers are actively exploiting a critical remote code execution vulnerability in the Fastjson library tracked…
1. Check Point patched a critical authentication bypass vulnerability in SmartConsole tracked as CVE-2026-16232 which is currently under active exploitation (The Hacker News). 2. Russian state-sponsored group Laundry Bear is exploiting a zero-click vulnerability in Zimbra Collaboration servers to steal emails and credentials (BleepingComputer). 3. The Clop ransomware gang is conducting a data theft extortion campaign targeting internet-exposed PTC Windchill and FlexPLM instances (BleepingComputer). 4.…