Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

In August 2026, Microsoft released patches addressing over 400 vulnerabilities, including a serious zero-day exploit identified as CVE-2026-68820. This particular flaw is a use-after-free vulnerability affecting the Windows Ancillary Function Driver for WinSock (AFD.sys), which could allow a low-privileged local attacker to gain elevated privileges to the SYSTEM level. This means that attackers with local access could potentially execute malicious applications to take control of affected systems. The urgency of this update is underscored by the fact that the vulnerability is already being exploited in the wild. Users and organizations relying on Windows systems should prioritize applying these updates to mitigate potential risks.

+1 more
Read Original

Ivanti has released an update to address vulnerabilities in their Endpoint Manager (EPM) that could allow attackers to exploit systems remotely. These flaws could lead to the leaking of credentials for external SQL connections or even crashing the agent service, potentially disrupting operations for affected organizations. Companies using Ivanti EPM need to prioritize applying this update to safeguard against these security risks. The vulnerabilities underline the importance of keeping software up to date to protect sensitive data and maintain system stability.

Read Original

A security researcher known as Chaotic Eclipse has released a proof of concept (PoC) for a new zero-day vulnerability named ShieldBreak, affecting Microsoft Defender. This vulnerability successfully bypasses the previously issued patch for CVE-2026-50656, known as RoguePlanet, which was intended to address a race condition. If exploited, ShieldBreak could allow attackers to execute code with SYSTEM-level privileges on affected systems. This presents a serious risk to users of Microsoft Defender, as the flaw can potentially compromise the security of their devices. Companies using Microsoft Defender should take immediate action to assess their systems and apply necessary security measures to mitigate this risk.

Read Original

In March, two malicious LiteLLM packages were available on the Python Package Index (PyPI) for about 40 minutes, containing code designed to steal sensitive information. These packages could extract cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from any systems that installed them. According to CloudSEK, a dataset created from approximately 434,000 files that attackers collected has been linked to over 2,100 organizations potentially affected by this incident. The short availability window raises concerns about the security of third-party package repositories and the risks they pose to developers and organizations relying on them. Users and companies need to be vigilant about the software they install and consider implementing security measures to protect against such attacks.

Read Original

Spanish police have apprehended a man in Murcia who allegedly used deepfake technology to bypass video identity checks from a certificate provider, aiming to acquire digital signatures for financial fraud. The suspect is reported to have made 38 attempts to deceive the system, targeting over 30 individuals. While the police have not disclosed how many of these attempts were successful, the case came to light after the certificate provider raised concerns. This incident emphasizes the growing threat of deepfake technology being exploited for fraudulent activities, which poses significant risks to individuals and businesses alike, as digital signatures are crucial for verifying identities in various online transactions.

Read Original

SAP has identified a serious security flaw in its Commerce Cloud service, specifically affecting the Data Hub Adapter. This vulnerability, labeled CVE-2026-58231, carries a CVSS score of 10.0, indicating its severity. It stems from inadequate authorization checks and poor input validation, which could allow unauthenticated attackers to execute arbitrary code on affected systems. The flaw poses a significant risk as it could lead to unauthorized access and manipulation of data within the Commerce Cloud environment. SAP has released patches to address this issue, urging all users to implement them promptly to safeguard their systems.

Read Original

SonicWall has released patches for serious vulnerabilities found in its discontinued Global Management System (GMS) platform. These security flaws could enable attackers to execute arbitrary code remotely without authentication, potentially allowing access to sensitive information. Although the GMS platform is no longer supported, the existence of these vulnerabilities raises concerns about the security of any systems that might still be using it. Users and organizations that have not transitioned away from GMS should take immediate action to secure their environments. It's critical for businesses to stay vigilant about outdated systems, as they can still pose significant risks even after official support has ended.

Read Original

A security researcher known as Chaotic Eclipse has released a proof-of-concept (PoC) for a serious zero-day vulnerability dubbed ShieldBreak, affecting Microsoft Defender for Windows. This vulnerability allows attackers to bypass the existing patch for CVE-2026-50656, also known as RoguePlanet, which has a CVSS score of 7.8, indicating a significant security risk. The flaw could enable unauthorized access with SYSTEM privileges, putting users' systems at risk. This discovery is crucial as it highlights the weaknesses in Microsoft Defender's security measures, potentially exposing millions of users to exploitation. Companies using Microsoft Defender should remain vigilant and apply any available patches while monitoring for any signs of exploitation.

Read Original

Christopher Smith, CEO of Quantus, discusses the challenges of migrating to post-quantum cryptography, particularly in sectors like banking and healthcare. He reveals that many institutions still hold outdated cryptographic inventories, including default passwords and admin keys from former employees, which complicates the upgrade process. Smith explains that the larger key sizes required for post-quantum systems break previous assumptions about encryption protocols like IPsec, SSH, and TLS. This places a significant burden on organizations looking to upgrade their security measures, as user-held keys in blockchains create additional hurdles. The conversation raises awareness of the potential risks associated with a 'silent quantum break,' where vulnerabilities could be exploited without immediate detection. This situation emphasizes the urgent need for funding and resources to address these cryptographic challenges.

Read Original
Actively Exploited

Cisco has issued a patch for a serious vulnerability identified as CVE-2026-20349, which affects its Secure Firewall ASA and FTD devices. This flaw can be exploited remotely without the need for authentication, allowing attackers to launch Denial of Service (DoS) attacks against the devices. The ability to target these firewalls without prior access poses a significant risk to organizations that rely on Cisco's security solutions. Users of affected devices are urged to apply the updates provided by Cisco promptly to mitigate potential exploitation. The urgency of this patch reflects the growing trend of vulnerabilities being targeted in the wild, emphasizing the need for vigilant cybersecurity practices.

Read Original

A recent study by Picus Labs, detailed in their Blue Report 2026, reveals a mixed picture of enterprise cybersecurity defenses. The report, which analyzed over 338 million attack simulations, indicates that while organizations are becoming more adept at thwarting loud and apparent attacks, their defenses against quieter, more subtle threats have seen little improvement. This suggests that while companies may be better prepared for obvious threats, they remain vulnerable to stealthy attacks that can go unnoticed. As attackers evolve their tactics, enterprises need to focus on enhancing their defenses against these less visible threats to ensure comprehensive protection.

Read Original

A recent survey by NetFoundry reveals that Chief Information Security Officers (CISOs) and Chief Technology Officers (CTOs) anticipate a 14% increase in their organizations' attack surface due to AI deployments over the next year. Most organizations lack visibility into these AI tools, which raises concerns about employees using unapproved applications without oversight. About 90% of the surveyed executives expressed worry over this issue, indicating a significant gap in security management. As businesses increasingly adopt AI technologies, the pressure to secure these systems is mounting, posing risks not just to individual organizations but also to broader cybersecurity frameworks. This situation calls for immediate attention to ensure that AI use does not lead to vulnerabilities that could be exploited by attackers.

Read Original

The Kimwolf botnet has been revamped following police actions that previously dismantled it, including server seizures and the arrest of an alleged operator. Researchers indicate that the botnet now employs tactics to disguise its attacks as normal Chrome web traffic, complicating detection efforts. Additionally, it retrieves commands from the Ethereum blockchain, enhancing its resilience against future takedowns. This evolution poses a significant challenge for cybersecurity experts as it becomes harder to trace and mitigate. The resurgence of Kimwolf highlights ongoing vulnerabilities in network security and the persistent threat posed by sophisticated botnets.

Read Original

Delta Air Lines is investigating a rogue Wi-Fi network called 'Delta WiFi Fast' that was reportedly set up by passengers on a flight returning from the DEF CON hacker conference. This unauthorized network raised concerns as it could potentially allow for malicious activities among the passengers. DEF CON is known for attracting hackers and tech enthusiasts, which adds to the seriousness of the situation. Delta has not provided details on any specific security breaches or compromises, but the incident underscores the risks associated with in-flight Wi-Fi and the need for vigilance among airlines and passengers alike. As investigations continue, the airline is likely assessing the implications for onboard security protocols.

Read Original

A man has been apprehended after a glitch in face-changing software revealed his identity while he was attempting to defraud a security company that issues digital certificates in Spain. These certificates are essential for online authentication and electronic signatures, making them highly valuable targets for cybercriminals. The individual exploited vulnerabilities in the certificate issuance process, which could have serious implications for online security and trust in digital communications. The incident raises concerns about the effectiveness of current security measures in protecting against such deceptive tactics. Authorities are now investigating the case further to prevent similar attacks in the future.

Read Original
Page 1 of 334Next