Chrome/V8 zero-day actively exploited and added to the CISA KEV catalog
Google has released an urgent update for Chrome that fixes 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 engine already exploited in the wild. The flaw can allow a remote attacker to execute arbitrary code in the browser sandbox through a specially crafted HTML page. CISA has added the bug to the Known Exploited Vulnerabilities catalog, confirming…
Read the article →Zero-day SonicWall SMA 1000 exploited in the wild
SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authentication command injection flaw. Researchers and various advisories cite the possibility that attackers…
Read the article →McKesson under pressure after a cyber incident and ShinyHunters’ claim
McKesson, the large Texas-based pharmaceutical distributor, has confirmed a security incident that is causing disruptions to its systems. The company said the intrusion involves a third-party application and that the investigation is still in…
Read the article →PaperCut: emergency patch 2 closes the exploited RCE chain
PaperCut has released Emergency Patch Release 2 after researchers demonstrated that the first fix could be bypassed against a pre-authentication remote code execution chain that was already being actively exploited. The flaw affects PaperCut…
Read the article →CISA adds Oracle HTTP Server/WebLogic Proxy Plug-in to KEV catalog for active exploitation
CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog after finding evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The flaw is a critical access control vulnerability…
Read the article →CISA adds four critical vulnerabilities to KEV catalog for active exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming their active exploitation in the wild. Among them are an authentication flaw in…
Read the article →Russian campaign against Zimbra with zero-click exploit and theft of emails and 2FA codes
Several Russia-linked groups exploited an as-yet-unknown vulnerability in Zimbra for months to target government and strategic organizations in the West. The vector was particularly dangerous because simply opening or even just viewing the email…
Read the article →WordPress wp2shell: the exploit chain fueling mass scanning
Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, have been combined into the chain known as wp2shell, capable of going from an unauthenticated request all the way to full site compromise. After the patch was…
Read the article →Two million cars with dealer-installed anti-theft systems are exposed via Bluetooth
Researchers at the University of California, San Diego, have discovered that at least 2.2 million cars with dealer-installed anti-theft systems are vulnerable to a Bluetooth attack. An attacker could lock or unlock the doors…
Read the article →Active exploit on SharePoint CVE-2026-50522 after Patch Tuesday
Microsoft SharePoint has come under attack following the publication of a public proof-of-concept for CVE-2026-50522, a critical deserialization flaw that can lead to remote code execution. Researchers at watchTowr and other analysts have observed…
Read the article →
Check Point SmartConsole: authentication bypass actively exploited
Iranian attacks against Siemens and Schneider industrial systems
The Adobe Acrobat for Chrome flaw exposes WhatsApp Web data
Ransomware on Japan’s cold chain
Ubuntu snap-confine: the race condition that leads to local root
Kratos taken down, the phishing kit behind thousands of campaigns per month
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
CISA Demonstrates the Defensive Gap in Two Critical Infrastructures
Check Point SmartConsole: authentication bypass actively exploited
Iranian attacks against Siemens and Schneider industrial systems
The Adobe Acrobat for Chrome flaw exposes WhatsApp Web data
Ransomware on Japan’s cold chain
Ubuntu snap-confine: the race condition that leads to local root
Kratos taken down, the phishing kit behind thousands of campaigns per month
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
CISA Demonstrates the Defensive Gap in Two Critical Infrastructures- Brazilian banking trojan expanding into Portugal
- North Korean ClickFake campaign targets Web3 professionals
- Fake alert app in Bahrain distributes Android spyware
- HollowGraph uses Microsoft 365 calendars as a covert C2 channel
- OpenAI: the models escaped the sandbox and hit Hugging Face
- Google launches CodeMender and Gemini 3.5 Flash Cyber to uncover vulnerabilities
- OT security: the ‘air gap’ is a myth and resilience must be designed
- PR3TACK wants to map threats before attackers use them











