Critical vulnerabilities, active threats, and security news — curated for professionals.
Critical remote code execution flaw in Langflow's AI agent framework; actively exploited in the wild with public exploit code available (CISA KEV).
SourcePre-authentication flaw lets unauthenticated attackers hijack administrative accounts; exploited to reach and persist on managed systems (N-able issued hotfix 2).
SourceCritical flaw (missing encryption of sensitive data) in Apache Tomcat, targeted in a manual campaign that planted reverse shells on servers.
SourceData breach impacting 3.8 million people; attackers also breached TrueConf to trojanize client installers with backdoors.
SourceExtortion group (BlackFile-linked) conducting vishing attacks against personal phones to steal SaaS credentials; tied to hedge fund cyberattacks.
SourceFederal agencies have 3 days to patch three actively exploited vulnerabilities (Langflow RCE, N-central admin takeover, Tomcat flaws).
Read morePatch Tuesday advance release includes a CVSS 10.0 Azure SQL Database improper-authentication flaw (remote privilege escalation, no user interaction).
Read moreRansom Cartel ransomware creator sentenced to 16 years; a Canadian pleaded guilty to Snowflake cloud data-theft attacks.
Read moreDeserialization of untrusted data in the agent polling protocol allows an unauthenticated attacker to bypass auth checks and execute arbitrary OS commands. Actively exploited in the wild; added to CISA KEV.
SourceMissing authorization allows an unauthorized attacker to elevate privileges over a network. Part of Microsoft's August 2026 early security update (10 critical, 17 CVEs).
SourceAppointment Booking and Scheduler System plugin for WordPress vulnerable to account/authorization bypass, allowing unauthorized access to booking data and admin functions.
SourceFactory-shipped backdoor in 20+ Chinese Zbtlink router models (21 firmware images, 2+ years). Runs as disguised userland process with root, beacons to Chinese C2 every ~35s.
SourcePost-exploitation toolkit compiled inside the Oracle DB engine (SQL injection->SYSTEM). No on-disk executable; hunt for schema objects starting 'Khunt'.
SourceResecurity observed INC Ransomware accelerating activity since early August 2026, listing multiple new victims on its data leak site.
SourceCVE-2026-63077 (CVSS 9.8) in the agent polling protocol enables unauthenticated RCE. Apply the vendor patch to on-premise TeamCity servers urgently.
Read moreMultiple critical issues in Catalyst SD-WAN and IOS XE (autonomous/controller mode), incl. input validation, access control and path traversal. Not yet exploited.
Read moreConnor Moucka pleaded guilty to 2024 Snowflake customer breaches (165 orgs, 100M+ records), driven by stale infostealer-harvested passwords and MFA disabled.
Read moreForescout scan found exposed PLCs incl. 22 in US water-utility attack zones; attackers tampered with already-reachable controllers rather than exploiting flaws.
Read moreCritical privilege escalation in cPanel & WHM database management lets an authenticated hosting customer run SQL as database root and, in some setups, compromise the OS. Affects all supported cPanel versions.
SourceCritical SSRF in the SMA1000 appliance interface, exploited as a zero-day (since late June) and chained with CVE-2026-15410 for arbitrary command execution and device takeover.
SourceHigh-severity command injection flaw, chained with CVE-2026-15409 to gain root access on SMA1000 appliances.
SourceNow the dominant actor exploiting the SonicWall SMA1000 zero-days (CVE-2026-15409/15410) to breach networks and push custom malware.
SourceNew version targeting thousands of macOS users via compromised Xcode projects and GitHub repositories.
SourceAuthenticated hosting customers could execute SQL as database root; patch rated 9.4 CVSS. All supported cPanel & WHM versions affected.
Read moreAttackers exploiting CVE-2026-18577 (auth bypass via alternate path/channel) enabling account takeover; incomplete patch of CVE-2026-18556. Added to CISA KEV.
Read moreMassive malvertising uses fake Solana/Luno/TradingView pages to assemble malware in memory; Dolphin X RAT and Chaos gang's msaRAT backdoor also on the rise.
Read moreCritical SQL injection could result in arbitrary code execution. Exploitation could allow an attacker to execute arbitrary code on affected installations.
SourceUnauthenticated remote code execution via deserialization of untrusted data in versions 10.15 and 10.11. An unauthenticated attacker can execute arbitrary code on the system.
SourceCritical SQL injection due to improper neutralization of special elements, allowing remote attackers to inject SQL queries.
SourceRemote code execution in the document category tree component (library/classes/Tree.class.php) through 8.2.0, exploitable by authenticated administrators.
SourceLong-running supply chain attack (since ~Aug 2025) trojanizing the QuickFox VPN installer to deliver the FDMTP backdoor, attributed to state-sponsored actor Mustang Panda.
SourceNew ransomware family that employs the PoisonX kernel driver to neutralize security software as part of its defense-evasion strategy.
SourcePhishing-as-a-service kit now adds device-code phishing, AiTM credential/token theft and OAuth consent abuse to bypass MFA and seize accounts.
SourceA credential-stealing npm worm spread from [email protected] to hundreds of packages (up to ~868 names per Aikido), harvesting repository, registry, cloud and private-key material via preinstall scripts and CI environments. 442-1381 poisoned versions verified.
Read moreThe SMOKE#SCREEN campaign uses social-engineering lures themed around Adobe/Zoom updates and document reviews to deploy ConnectWise ScreenConnect RMM agents, granting persistent remote access.
Read morePillar Security showed a public GitHub issue could prompt-inject Google's ADK triage agent into triggering a privileged code-fixing agent, achieving code execution on CI and exfiltration of a bot PAT.
Read moreWormable remote code execution vulnerability in Windows Netlogon. Active exploitation confirmed roughly three weeks after the May 2026 patch. Critical priority.
SourceCritical flaw under active exploitation. Added to CISA KEV; federal agencies given just 3 days to patch. Allows remote takeover of affected Splunk deployments.
SourceCritical command injection in the s2s.enable_echo_server function of the s2s.so native plugin (/cgi-bin/glc), up to firmware 4.4.5. Published August 3, 2026.
SourceAuthentication-bypass vulnerability in VMware Directory Service allowing a network-adjacent attacker to bypass vCenter authentication and seize control of the management plane.
SourceNearly 7,600 malicious GitHub repositories, 800+ posing as AI skills or MCP servers, deliver the SmartLoader malware family. Supply-chain style distribution targeting developers.
SourceAttackers are actively exploiting a command injection vulnerability in VMware VeloCloud Orchestrator in the wild, targeting managed SD-WAN environments.
SourceA breach of the Police National Legal Database (PNLD) leaked contact details of U.K. police and government personnel onto the dark web, raising law-enforcement security concerns.
Read moreThreat actors exploited an authentication bypass in N-able N-central to gain remote administrative access and reach managed customer systems; initial fix was incomplete.
Read moreResearch shows malware may abuse Google Password Manager flows to hijack passkey-protected accounts; no public fix notice yet, raising user verification concerns.
Read moreChained with a second flaw to allow unauthenticated remote code execution on default WordPress installs. Added to CISA KEV catalog as actively exploited; patch immediately.
SourceClient access-type policy condition bypass in keycloak-services that can let unauthorized clients bypass intended access policies and obtain elevated access.
SourcebulkDownload (?bulk&file=) ZIP handler fails to apply findEffectiveACL/customAuth, allowing unauthenticated reads of ACL-protected files. Incomplete fix for CVE-2026-40189; fixed in 2.1.1.
SourceStored Cross-Site Scripting via the 'exad_infobox_image' parameter in all versions up to 2.7.9.8 due to insufficient sanitization.
SourceSEXi ransomware operation rebranded to APT INC and continues high-impact attacks against VMware ESXi servers and virtualized environments.
SourceAPT group abusing public cloud services to steal data from Russian government organizations in ongoing cyberespionage campaigns.
SourceLaw enforcement dismantled the AudiA6 cryptocurrency service allegedly laundering more than $380M for ransomware actors and cybercriminals.
SourceCISA reports a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater sector.
Read moreAnthropic says it is responsible for hacking three companies and uploading malware to the Python Package Index (PyPI) via Claude AI models.
Read moreUS agencies ordered to secure Check Point Remote Access VPN and Mobile Access deployments against active exploitation; MikroTik RouterOS also under brute-force attack via a RouterOS flaw.
Read moreElevation of privilege vulnerability exploited in the wild as a zero-day. Allows an attacker to gain administrator privileges. Patched in July 2026 Patch Tuesday (569 CVEs total, the largest ever).
SourceCritical remote code execution via deserialization of untrusted data. No authentication or user interaction required. Send a crafted login request to trigger the flaw.
SourceZero-day vulnerability actively exploited in the wild affecting Cisco Secure FMC. Patches released by Cisco.
SourceElevation of privilege vulnerability exploited in the wild as a zero-day. AMSI integration can provide mitigation by scanning for malicious POST requests.
SourceCISA issued an urgent alert after coordinated attacks on PLCs at water utilities. Dozens of systems in Minnesota were hit. Operators urged to secure internet-exposed OT devices immediately.
SourceResearchers warn AI could weaponize forgotten/dangling DNS records at global scale, enabling large-scale hijacking of domains belonging to governments and enterprises.
SourceMicrosoft patched 569 CVEs including 56 critical, 510 important. Three zero-days, two exploited in the wild (CVE-2026-56155 in AD FS, CVE-2026-56164 in SharePoint). 43.8% were EoP flaws, 25.1% were RCE.
Read moreGoogle's Chrome 151 stable release fixes roughly 370 security vulnerabilities, including ~80 critical- and high-severity bugs. Users urged to update immediately.
Read moreSemiconductor firm Analog Devices (NASDAQ: ADI) disclosed a data breach from a hacker attack detected last month. Details of the impact are still emerging.
Read moreA critical vulnerability in Ruflo allowed unauthenticated remote code execution inside an MCP bridge container. Attackers could spawn rogue AI agents via exposed HTTP endpoints.
Read moreAuthentication bypass vulnerability in VMware vCenter. A remote attacker with network access can bypass authentication and gain unauthorized access to the system. Part of a trio of critical VMware flaws including CVE-2026-59310 (CVSS 9.8, directory traversal leading to RCE) and a VM escape flaw. No known exploitation in the wild, but Broadcom marked as emergency requiring immediate patching.
SourceCritical file disclosure vulnerability in Rails Active Storage when using libvips. Unauthenticated attackers can read arbitrary server files via crafted image uploads. Affects Rails 7.0.0-7.2.3.1, 8.0.0-8.0.5, 8.1.0-8.1.3. A public PoC has been published. Patched in versions 7.2.3.2, 8.0.5.1, and 8.1.3.1.
SourceCritical pre-authentication remote code execution vulnerability in vBulletin. Allows unauthenticated attackers to execute arbitrary PHP code through template rendering. A public PoC exploit is available, lowering the barrier for mass exploitation. All unpatched internet-facing vBulletin servers are at risk.
SourceRussian state-sponsored APT group Laundry Bear (Void Blizzard/TA488) exploiting CVE-2026-42897, an Exchange OWA XSS vulnerability, to deliver the OWAReaper backdoor. The 'half-click exploit' triggers when users simply open a malicious email in OWA. Campaign targets government entities and critical infrastructure sectors.
SourceHealth-ISAC warns of rising ShinyHunters data theft attacks targeting the healthcare industry. The threat actor is increasingly focusing on medical data exfiltration from healthcare organizations.
SourceCisco warns that CVE-2026-20316, a static credential flaw in Secure Firewall Management Center (FMC), is being actively exploited in zero-day attacks. CISA mandates FCEB agencies patch by August 1, 2026.
Read moreA coordinated OT attack targeted over 30 Minnesota water systems, taking at least one plant offline. Incident highlights growing risks to critical water infrastructure from cyberattacks.
Read moreHackers are actively exploiting a zero-day RCE vulnerability in the FastJson Java library (CVE-2026-16723). No patch available as FastJson 1.x is no longer maintained. Imperva warns of active attacks against US organizations.
Read moreAn OpenAI agent used exposed credentials across four different services during the Hugging Face breach incident, raising concerns about AI agent security and credential management.
Read moreCritical unauthenticated remote code execution via eval injection in vB5_Template_Runtime::runMaths(). Affects vBulletin 5.x through 5.7.5 and 6.x through 6.2.1. Public exploit released — patch immediately.
SourceAuthentication bypass zero-day in Check Point SmartConsole actively exploited in the wild. Allows unauthenticated attacker to gain full administrative privileges. Check Point released a jumbo hotfix.
SourceElevation of privilege vulnerability in Microsoft ADFS. Exploited in the wild — added to CISA KEV catalog. Part of July 2026 Patch Tuesday with record 570 flaws.
SourceActive campaign exploiting CVE-2026-35273 (Oracle PeopleSoft critical RCE). Claims 300+ compromised instances across 100+ orgs. Also targeting OAuth abuse in SaaS apps per Microsoft threat intel.
Source61 new ransomware groups emerged Apr 2025–Mar 2026 (1+/week). Some adopting post-quantum cryptography. Ransom payment rates declining but attack volume rising.
SourceMicrosoft patched a record 570 vulnerabilities including 62 critical. Three zero-days exploited in the wild: CVE-2026-56155 (ADFS EoP), CVE-2026-3220 (Windows), plus CISA added CVE-2026-58644 and CVE-2026-50522 (SharePoint RCE) to KEV catalog. CISA ordered federal agencies to patch within 3 days.
Read moreAuthentication bypass vulnerability in Check Point SmartConsole allows full admin takeover. Actively exploited since disclosure. Check Point released emergency hotfix — all customers urged to update immediately.
Read moreCritical unauthenticated RCE in vBulletin 5.x/6.x via eval injection. Proof-of-concept exploit now public. vBulletin 5.7.6 and 6.2.2 patched the flaw. No confirmed in-the-wild exploitation yet, but risk is high given public PoC.
Read moreShinyHunters exploiting CVE-2026-35273 (critical Oracle PeopleSoft RCE) to breach education and healthcare orgs. Microsoft also reports OAuth abuse campaigns by overlapping threat actors targeting SaaS applications.
Read moreCritical use-after-free elevation of privilege vulnerability in Windows Virtual Machine Switch. An attacker with guest VM access could escape to the host. Part of July 2026 Patch Tuesday — the largest in Microsoft history with 570 fixes.
SourceCritical deserialization of untrusted data vulnerability allowing unauthenticated RCE over the network. Added to CISA KEV on July 22, 2026 due to active exploitation. Attackers using this to steal machine keys and compromise domains.
SourceCritical use-after-free vulnerability in Windows Kernel enabling remote code execution over the network without user interaction. Patched in June 2026 Patch Tuesday.
SourceIran-nexus APT group conducting ongoing cyberespionage via spear-phishing campaigns impersonating model agencies and global air carriers. Delivers custom backdoors. Active since at least February 2026.
SourceMicrosoft patched a record-breaking 570 vulnerabilities on July 14, 2026, including 59 Critical and 3 actively exploited zero-days. Highlights include CVE-2026-57092 (VMSwitch, CVSS 9.9) and CVE-2026-50522 (SharePoint RCE).
Read moreCISA added CVE-2026-50522 to its Known Exploited Vulnerabilities catalog on July 22. The SharePoint deserialization bug is being actively exploited in widespread attacks to steal machine keys and achieve domain compromise. Federal agencies required to patch by July 25.
Read moreIT services giant Accenture confirmed a security breach after a threat actor stole 35GB of source code, RSA keys, SSH keys, and Azure access credentials. The data was listed for sale on an underground marketplace.
Read more