organization · 33 records
CISA

Apache Syncope vulnerability enables arbitrary SQL command execution
Rapid7 released a public proof-of-concept script for a critical authentication bypass vulnerability in Check Point SmartConsole that allows unauthenticated attackers to gain administrative privileges.

Attackers exploit critical Fastjson vulnerability despite lack of security patches
Security firms report active exploitation of a critical Fastjson RCE vulnerability with no patched version currently available.

CBI probes $6 million tech, identity theft fraud involving US citizens
The Central Bureau of Investigation has filed a case against an Ahmedabad-based man for allegedly running a $6 million tech support and identity theft fraud targeting US citizens.

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
Security agencies and firms report active exploitation of vulnerabilities in Zyxel switches and Veeam software.

Cisco Secure Email Gateway Flaw Exploited in the Wild
A critical vulnerability in Cisco Secure Email Gateway is being actively exploited, prompting emergency patching requirements.

Hackers target water systems in Colorado
Hackers compromised the systems of two small water utilities in Colorado, although service remained uninterrupted.

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
Researcher Asim Manizada has released proof-of-concept exploits for four memory-safety vulnerabilities in the Linux kernel that allow local privilege escalation to root.

Critical vulnerability discovered in Cisco Secure Firewall Management Center software
CISA added a newly disclosed zero-day vulnerability in Cisco Secure Firewall Management Center to its Known Exploited Vulnerabilities catalog following reports of active exploitation.

Attackers exploit critical JFrog Artifactory vulnerability to create administrator tokens
Threat actors are exploiting a newly patched critical security flaw in JFrog Artifactory to mint administrator tokens shortly after the vulnerability was disclosed.

Hackers exploit PaperCut software vulnerabilities to steal credentials from educational institutions
Threat actors are exploiting PaperCut software vulnerabilities to conduct credential theft at educational institutions in the U.S. and Europe.

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has patched multiple critical vulnerabilities, including a path traversal flaw being actively exploited in the wild.

Google releases Chrome security update for actively exploited V8 vulnerability
Google has patched a high-severity V8 type confusion vulnerability in Chrome that is currently being exploited in the wild.

JADEPUFFER group targets AI infrastructure using new ENCFORGE ransomware strain
A threat actor known as JADEPUFFER deployed a new Go-based ransomware strain called ENCFORGE targeting AI model files and infrastructure after exploiting a remote code execution vulnerability in Langflow.

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control
cPanel released patches for a critical vulnerability allowing root-level code execution via domain parking or addon domain functionality.

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has patched a high-severity privilege escalation vulnerability in the Pixel Cellular Modem that is currently being exploited in targeted attacks.

Russian hackers exploit Zimbra vulnerability to steal email data
A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal email data and authentication codes from Western government and commercial organizations between July 2025 and early 2026.

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
A Chinese-speaking threat actor exploited a critical ownCloud vulnerability to steal files from a Philippine nuclear research organization.
US Tracking Cyber Threats Against Nearly 20 Ships Worldwide
US government agencies are investigating potential cyber threats against nearly 20 commercial shipping vessels globally.

Zoom releases security updates to address critical Windows vulnerability
Zoom has released security updates to address a critical vulnerability in its Windows clients that could allow unauthenticated attackers to take over user accounts, along with three other high-severity flaws.

JetBrains urges TeamCity users to update following critical security vulnerability
JetBrains is urging customers of on-premise versions of TeamCity to update following disclosure of a critical vulnerability allowing unauthenticated remote code execution.

Ransomware attackers exploit vulnerabilities in PTC Windchill and FlexPLM software
Ransomware-affiliated attackers are exploiting vulnerabilities in PTC Windchill and FlexPLM to deploy web shells and conduct double extortion data theft campaigns.

CISA adds exploited SharePoint zero day vulnerability to known exploited vulnerabilities catalog
CVE-2026-44747 disclosed: SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modific

Linux kernel update addresses vulnerability in action lifecycle management
CVE-2026-53264 disclosed: In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is po

Cyberattack hits over thirty water systems in Minnesota causing outages
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, causing outages and communications failures in several locations.

Arista patches zero-day vulnerability in VeloCloud Orchestrator deployments
Arista patched a maximum-severity zero-day command injection vulnerability in VeloCloud Orchestrator deployments that is being actively exploited by attackers.

Public exploit released for patched vBulletin code execution vulnerability
Public exploit details were released for a patched pre-authentication code execution flaw in vBulletin affecting unpatched self-hosted servers with no confirmed in-the-wild attacks.

RedisBloom security vulnerability discovered in versions before 2.8.20
CVE-2026-25589 disclosed: RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE

China-linked group targets global organizations with new malware loader
Group-IB analysis of an exposed Alibaba Cloud server revealed a China-nexus operation named JadeProx using the TriBack Loader to attack government, healthcare, and education organizations across Asia and Latin America.

New exploit allows users to impersonate domain controllers in Active Directory
Researchers published an exploit for a vulnerability in Microsoft's Active Directory Certificate Services that enables low-privileged users to impersonate Domain Controllers.

Qilin ransomware gang exploits critical Palo Alto Networks VPN vulnerability
The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN to breach corporate networks.