Two members of Congress have formally requested that a government watchdog agency investigate the extent and oversight of federal agencies’ use of hacking tools, including spyware, against Americans. The lawmakers seek a public report detailing the findings. The request, sent Friday to the Government Accountability Office (GAO), was made by Senator Ron Wyden, a Democrat [...]
Cisco has issued a new set of security advisories detailing critical vulnerabilities across its Crosswork platforms and Secure Workload Software. These updates are part of an ongoing, comprehensive internal security review by the networking giant. The identified security flaws, several with maximum or near-maximum CVSS scores, underscore the persistent threat landscape for enterprise security…
A critical GitLab vulnerability, identified as CVE-2026-19478, is being actively exploited in the wild shortly after its public disclosure. This severe code injection flaw allows unauthenticated attackers to compromise publicly accessible GitLab projects, enabling them to modify, delete, or rewrite project data without needing credentials or user interaction, according to a report by preemptive…
Microsoft has issued a critical alert regarding a maximum-severity security flaw, CVE-2026-69836, within its Microsoft Entra ID service, formerly known as Azure Active Directory. The company confirmed that this remote code execution vulnerability has already been exploited in the wild, posing a significant threat. However, Microsoft has stated that no immediate action is required from [...]
Citrix has issued critical security updates to address two significant vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products. The patches are particularly important for organizations using customer-managed NetScaler instances, as one of the flaws allows for a critical-severity authentication bypass, potentially granting unauthorized access. The vulnerabilities were disclosed…
A critical security vulnerability has been discovered in isolated-vm, a widely-used Node.js sandbox library, potentially allowing attackers to escape the confined environment. The flaw, identified by cybersecurity researchers, impacts numerous applications that rely on this library for running untrusted JavaScript code securely. This discovery highlights ongoing challenges in maintaining robust…
AI security firm Adversa AI has disclosed a novel attack technique, codenamed “Cryptographic Context Injection,” that it claims can compel xAI’s Grok chatbot to leak sensitive user information to an attacker. This exploit reportedly allows an attacker to obtain a user’s name, approximate location, subscription tier, and current conversation prompts by tricking Grok into summarizing [...]
The U.S. government has issued a stark warning about an “active threat” leveraging artificial intelligence (AI) to generate exploit scripts targeting critical infrastructure organizations. This new wave of cyber activity specifically targets Siemens S7 Series Programmable Logic Controllers (PLCs) for reconnaissance and capability development, though the scope is believed to be broader than just…
This week’s cybersecurity landscape is dominated by threats leveraging trusted components for malicious purposes, underscoring the persistent challenges in securing digital infrastructure. From the abuse of signed drivers to the exploitation of legitimate applications, attackers continue to find innovative ways to bypass defenses, making the need for robust cybersecurity measures more critical…
Cybersecurity researchers have uncovered a new threat dubbed “CDN Tsunami,” which exploits how major content delivery networks (CDNs) handle HTTP/3 traffic. These attacks can amplify low-bandwidth requests into massive floods directed at origin servers, potentially leading to significant service disruptions. The findings highlight a critical vulnerability in how CDNs bridge the gap between modern…
A bipartisan bill aimed at combating organized retail theft is gaining traction in Congress, though some advocacy groups warn it could lead to expanded surveillance powers. The Combating Organized Retail Crime Act, or CORCA, seeks to create a new coordination center within Immigration and Customs Enforcement (ICE) to share information and prosecute large-scale theft operations. [...]
Researchers at the University of Massachusetts Amherst have uncovered a significant security vulnerability in Visa contactless credit cards, demonstrating a method to revive expired cards for real-world purchases by manipulating the expiration date read by point-of-sale (POS) terminals. This “Zombie Card” attack, as it’s been dubbed, bypasses cryptographic protections, raising concerns about the…
Cybersecurity researchers have revealed a critical vulnerability in the popular Elementor Pro WordPress plugin, identified as CVE-2026-32475. This flaw, carrying a severe CVSS score of 9.0, could allow unauthenticated attackers to execute arbitrary code remotely on vulnerable websites. The vulnerability stems from an issue within the Forms module’s File Upload field, specifically how it handles…
Cybersecurity researchers have successfully demonstrated a remote Spectre attack targeting Cloudflare Workers, achieving a significant increase in data leakage speed. This advanced attack, detailed in a recent paper, managed to exfiltrate a JSON Web Token (JWT) from a co-located Worker in Cloudflare’s production environment at a rate of up to 12 bits per second. This [...]
Cybersecurity researchers at Hunt.io have detailed a large-scale attack campaign, codenamed Operation CameraSwarm, that compromised over 14,530 Dahua devices between June and July 2026. The campaign leveraged a combination of credential attacks, two critical authentication-bypass vulnerabilities, and a peer-to-peer (P2P) relay technique to gain unauthorized access to surveillance systems. The…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation in the wild. This move highlights the ongoing threat posed by these security flaws, particularly for organizations that have not yet applied the available patches. The inclusion signifies that these vulnerabilities…
A sophisticated, custom-built JavaServer Pages (JSP) web shell has been discovered deployed by threat actors targeting critical vulnerabilities in PTC Windchill and FlexPLM servers. Cybersecurity firm ReliaQuest has detailed how this bespoke tool, specifically crafted for Product Lifecycle Management (PLM) software, acts as a powerful extortion platform, enabling extensive data theft and remote…
Critical vulnerabilities affecting open-source artificial intelligence (AI) platform MLflow and operational technology (OT) software FUXA are currently under active malicious scanning and exploitation. These security weaknesses, identified as CVE-2026-64849 in MLflow and CVE-2026-25895 in FUXA, pose significant risks to organizations relying on these platforms for machine learning operations and…
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, which could allow attackers to silently exfiltrate data from connected applications with a single click on a crafted link. The flaws leverage an undocumented URL parameter that the AI assistant itself revealed during Varonis’s security research. Microsoft was notified of the [...]
Hardware wallet manufacturer SafePal has confirmed a significant data breach affecting approximately 39,798 customers. An authorization flaw within an order-tracking plug-in led to the exposure of sensitive customer information, including names, email addresses, shipping addresses, and phone numbers. The company has begun notifying all affected individuals via email, urging vigilance against…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting the open-source distributed computing framework Ray to its Known Exploited Vulnerabilities (KEV) catalog, confirming evidence of active exploitation. This designation for CVE-2025-62593, carrying a CVSS score of 9.4, highlights a significant risk for organizations utilizing Ray…
GitLab has released urgent security updates to address a critical vulnerability (CVE-2026-19478) in its self-managed Community Edition (CE) and Enterprise Edition (EE) software. This flaw, rated Critical with a CVSS score of 9.4, could permit an unauthenticated attacker to remotely alter or delete public projects and user data. The company issued this patch outside its [...]
A critical security flaw discovered in the Forminator Forms WordPress plugin, which boasts over 600,000 active installations, could enable unauthenticated attackers to execute arbitrary code on vulnerable websites. This significant vulnerability, designated CVE-2026-15748, carries a severe CVSS score of 9.8 out of 10.0, highlighting its potential for widespread damage. The flaw was identified and…
A cybercrime group known as BlackFile continues to target organizations across various sectors, including financial services, with a persistent wave of voice-phishing and extortion attacks. The group, tracked by Google Threat Intelligence Group as UNC6671 and associated with the broader threat actor The Com, has been actively seeking new victims as of late last week, [...]
Cybersecurity researchers have identified a significant vulnerability within Snowflake’s public snowflakedb/snowflake-connector-net GitHub Actions workflow, a flaw that could have allowed attackers to execute commands using internal Jira credentials. The issue, present in a specific workflow file, was discovered by Wiz and reported to Snowflake on June 23, 2026. While Snowflake has since patched…
The cybersecurity landscape remains a dynamic battleground, with sophisticated threats continually emerging. This past week has highlighted a persistent reality: even seemingly minor vulnerabilities can be exploited to cause significant damage. From critical infrastructure to everyday applications, attackers are leveraging a mix of novel exploits and well-trodden paths to compromise systems and…
Security researchers have detailed a sophisticated two-stage exploit chain targeting Unisoc modem firmware, a critical component in many Android smartphones. This vulnerability, achieved through a VoLTE video call, grants attackers full access to the Android kernel. As of August 2026, the chipset maker, Unisoc, has yet to issue a fix for this severe security flaw, [...]
As organizations increasingly integrate artificial intelligence (AI) agents into their operations, a significant vulnerability is emerging within the Model Context Protocol (MCP) server infrastructure. These servers, designed to enable AI agents to access and interact with enterprise tools and data, are inadvertently becoming prime targets for attackers. MCP servers can expose critical enterprise…
A newly identified Linux botnet, dubbed Evooo1Bot, is actively exploiting known vulnerabilities to compromise internet-facing devices, turning them into SOCKS proxies and bolstering botnet capabilities with features derived from the Mirai malware. Cybersecurity researchers at Fortinet FortiGuard Labs have detailed the botnet’s operations, which have been observed in the wild since July 2026.…
Cybersecurity researchers have identified a sophisticated attack campaign exploiting a critical vulnerability in Broadcom VMware vCenter, with evidence pointing towards a China-linked advanced persistent threat (APT) group. The exploitation of this newly patched flaw, identified as CVE-2026-59310, presents a significant risk to organizations relying on VMware’s virtualization software. The attacks…
A critical security vulnerability affecting SAP Commerce Cloud, identified as CVE-2026-58231, is currently facing active exploitation attempts. This severe flaw, rated a perfect 10.0 on the CVSS scoring system, stems from insufficient authorization checks and input validation within the SAP Commerce Cloud platform. Security researchers are urging immediate patching and mitigation efforts to…
A critical security vulnerability in Apple’s macOS, identified as CVE-2026-65400, is currently being actively exploited in the wild to deploy a Monero cryptocurrency miner, according to a warning issued by the Netherlands National Cyber Security Centre (NCSC). The authentication flaw affects the built-in Screen Sharing component, potentially allowing attackers already on the network to gain [...]