A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor affecting versions prior to 3.30.2 is actively exploited and presents severe security risks.
Gyazo confirmed a data breach after a server vulnerability was exploited to steal 23.6 million user records, underscoring risks in platform security.
An attacker hijacked an AI coding assistant session to distribute the Shai-Hulud worm within approximately 100 internal code repositories at a SaaS provider, resulting in theft of repository secrets and source code.
CISA has published guidance to help security teams deploy cyber decoys that improve detection of adversaries using legitimate credentials and living off the land tactics.
A critical vulnerability in the Issabel Framework allows unauthenticated remote OS command execution, actively exploited and posing a severe security risk.
CISA reports active exploitation of a critical vulnerability in ConnectWise ScreenConnect that risks unauthorized remote access.
CenterPoint Energy confirmed a breach where attackers exfiltrated customers' personal data, emphasizing the ongoing threats faced by critical utility providers.
Two critical vulnerabilities in mySCADA myPRO Manager allow unauthenticated attackers to access privileged management functions and send arbitrary SMS via connected GSM modems, affecting versions through 2.1.
Microsoft released out-of-band updates to address Remote Desktop Services failures and issues affecting Hyper-V and USB audio on certain Windows versions.
Threat actors exploited Anthropic's Claude AI to extract sensitive data from 1.8 million Android apps, highlighting growing risks of AI misuse.
Healthcare provider AdaptHealth confirmed that data of 4.1 million people was exposed in a July cyberattack tied to the ShinyHunters threat group, highlighting ongoing risks to healthcare organizations.
Cisco has confirmed active exploitation of a critical authentication bypass vulnerability (CVE-2026-20079) in its Secure Firewall Management Center software, risking enterprise defenses.
Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, significantly impacting enterprise security.
IDScan faces multiple lawsuits after hackers allegedly breached its identity verification service and sold data on over 153 million driver’s licenses, highlighting critical risks in personal data security.
A Linux backdoor named 'Ted' has been found in trojanized HAProxy builds at South Korean organizations, intercepting and modifying web traffic while requiring prior code execution on the host.
Aesto LLC, operating as Aesto Health, disclosed a data breach impacting over 9.5 million patients, highlighting critical risks to patient data security.
Berlin's city administration confirmed data theft following a ransomware attack by the Rhysida group, who are demanding ransom.
Microsoft Threat Intelligence analyzes the TerminalFix campaign, which leverages fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel for multistage intrusion.
A critical ownCloud vulnerability tracked as CVE-2023-49105 has been added to CISA's KEV catalog following exploitation by a Chinese-speaking threat actor targeting a Philippine nuclear research organization.
PaperCut released a second emergency patch addressing two actively exploited vulnerabilities in its NG and MF print management software after initial mitigations were bypassed.
Australian authorities arrested two men linked to the TeamPCP group known for extensive developer supply chain attacks, disrupting a significant threat actor.
CISA's red team assessments identified significant detection and response weaknesses in IT, cloud, and OT environments, revealing misconfigured Active Directory and excessive cloud permissions.
CISA has added CVE-2026-21962, an Oracle HTTP Server and WebLogic Server Proxy Plug-in vulnerability, to its Known Exploited Vulnerabilities Catalog due to active exploitation.
A critical code injection vulnerability in GitLab, CVE-2026-19478, is actively exploited shortly after disclosure, enabling unauthenticated attackers to modify or delete certain publicly accessible projects.
CISA added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities Catalog after active exploitation was observed.
CISA has included two actively exploited TrueConf Server vulnerabilities in its Known Exploited Vulnerabilities Catalog, emphasizing critical risks to federal agencies and beyond.
Citrix has patched critical authentication bypass vulnerabilities affecting NetScaler ADC and Gateway, impacting specific FIPS and NDcPP builds used on gateway and AAA servers.
Healthtech firm CareCloud disclosed a data breach impacting over 3.7 million patients, exposing sensitive healthcare information.
CISA warns of active exploitation of a critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions, enabling attacker code execution without user interaction.
CISA confirms ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability, posing increased risk to enterprise environments.
Two medium-to-high severity vulnerabilities in Johnson Controls Airwall could allow attackers to decrypt sensitive data and read arbitrary files, impacting critical infrastructure security.
The ShinyHunters group breached RingCentral in July, compromising personal data of 1.6 million user accounts.
Microsoft Threat Intelligence analyzes DeadLock ransomware, a Rust-based encryptor that employs decentralized victim communication and negotiation infrastructure alongside double extortion tactics.
LexisNexis took down several services after detecting unusual activity on servers managed by a third-party vendor, raising concerns about potential data breaches.
Gunra ransomware, a double-extortion RaaS exploiting VPN and RDP vulnerabilities, threatens government and critical infrastructure with data encryption and leaks.
The North Carolina Ports Authority confirmed a cyberattack on IT systems at multiple ports causing operational delays and highlighting risks to critical infrastructure.
Healthcare software provider Unlimited Technology Systems disclosed an October 2025 breach impacting over 3.8 million individuals and sensitive healthcare data.
A compromise affecting the Keyv and Cacheable npm packages is leading to reconsideration of token revocation policies due to an active malware that triggers upon premature token revocation.
A high-severity vulnerability in Thermo Fisher Applied Biosystems Genetic Analyzers allows modification of DNA data output files, risking inaccurate test results in healthcare settings.
Attackers use vishing via Microsoft Teams to impersonate IT support and deploy Chaos ransomware targeting organizations in North America through social engineering.
Cisco disclosed a high-severity zero-day vulnerability in its Secure Firewall Management Center involving static credentials, actively exploited to gain unauthorized access.
A coordinated cyberattack targeted operational technology at over 30 Minnesota community water systems in late July, causing outages and communication disruptions.
Broadcom published updates for critical VMware vulnerabilities in ESX, vCenter, Workstation, and Fusion enabling authentication bypass and VM escape with high severity.
A zero-day remote code execution vulnerability in the FastJson Java library is actively exploited by hackers against US organizations, posing a critical threat to enterprise applications.
Iranian state-backed group Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers in attacks across the Middle East, Africa, and South Asia, enhancing stealth and covert activity.
Attackers are exploiting a critical remote code execution vulnerability in Fastjson 1.x used in Spring Boot applications, enabling unauthenticated code execution with Java process privileges and no patch currently available.
Swiss rail manufacturer Stadler Rail faced a ransomware attack by the Everest gang targeting a shared supplier data exchange platform, refusing a $12.3 million ransom demand.
The Anubis ransomware group has claimed responsibility for a cyberattack on Coca-Cola's Fairlife brand and threatened to leak stolen data if ransom demands are not met.
A critical authentication bypass vulnerability in Tycon Systems TPDIN-Monitor-WEB2 allows unauthenticated attackers full administrative control, risking critical infrastructure disruptions.
A critical vulnerability in WordPress core enables unauthenticated attackers to execute code on default installations, prompting urgent patch releases.
Two hackers were sentenced for their 2024 attack on Transport for London, which disrupted 148 systems and forced a password reset for 27,000 employees, causing significant operational and financial impact.
US prosecutors charged three Russian nationals for operating a bulletproof hosting service that enabled ransomware gangs causing over $62 million in damages globally.
SAP released updates fixing a critical CVSS 9.9 out-of-bounds write vulnerability in NetWeaver ABAP that may allow authenticated attackers to corrupt memory and manipulate data.
CISA warns that remote code execution vulnerabilities are actively exploited in Joomla iCagenda and Balbooa Forms extensions through arbitrary file uploads, risking full compromise of affected sites.
Progress Software advises ShareFile customers to shut down Windows servers running Storage Zone Controllers due to a credible security threat, disabling account access as a precaution.