Zero-day SonicWall SMA 1000 exploited in the wild
SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authentication command injection flaw. Researchers and various advisories cite the possibility that attackers could chain them to achieve code execution and, in some cases, root access to the devices. SMA 1000 versions are used for secure remote access in…
Read the article →McKesson under pressure after a cyber incident and ShinyHunters’ claim
McKesson, the large Texas-based pharmaceutical distributor, has confirmed a security incident that is causing disruptions to its systems. The company said the intrusion involves a third-party application and that the investigation is still in…
Read the article →PaperCut: emergency patch 2 closes the exploited RCE chain
PaperCut has released Emergency Patch Release 2 after researchers demonstrated that the first fix could be bypassed against a pre-authentication remote code execution chain that was already being actively exploited. The flaw affects PaperCut…
Read the article →CISA adds Oracle HTTP Server/WebLogic Proxy Plug-in to KEV catalog for active exploitation
CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog after finding evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The flaw is a critical access control vulnerability…
Read the article →Suspected Iran-linked attack takes UK power plant offline
According to press sources cited by Help Net Security and Infosecurity Magazine, a British power plant remained offline for four days in July 2026 because of a cyberattack suspected to have been carried out…
Read the article →Russian campaign against Zimbra with zero-click exploit and theft of emails and 2FA codes
Several Russia-linked groups exploited an as-yet-unknown vulnerability in Zimbra for months to target government and strategic organizations in the West. The vector was particularly dangerous because simply opening or even just viewing the email…
Read the article →Active exploit on SharePoint CVE-2026-50522 after Patch Tuesday
Microsoft SharePoint has come under attack following the publication of a public proof-of-concept for CVE-2026-50522, a critical deserialization flaw that can lead to remote code execution. Researchers at watchTowr and other analysts have observed…
Read the article →WordPress wp2shell: the exploit chain fueling mass scanning
Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, have been combined into the chain known as wp2shell, capable of going from an unauthenticated request all the way to full site compromise. After the patch was…
Read the article →ServiceNow AI Platform CVE-2026-6875: Unauthenticated RCE Already Exploited
The CVE-2026-6875 vulnerability in the ServiceNow AI Platform allows an unauthenticated attacker to execute remote code on self-hosted instances. Searchlight Cyber disclosed it on July 14, 2026, and ServiceNow released patches the same day,…
Read the article →Qilin exploits CVE-2026-0257 in PAN-OS GlobalProtect to breach VPNs
The Qilin ransomware operation is abusing CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, to gain unauthorized access to corporate networks. The flaw affects GlobalProtect portals and gateways and especially impacts unpatched systems, which…
Read the article →
Ransomware on Japan’s cold chain
Fake alert app in Bahrain distributes Android spyware
Two million cars with dealer-installed anti-theft systems are exposed via Bluetooth
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
FalconFlank Exploit Released for CrowdStrike Falcon
Brazilian banking trojan expanding into Portugal
The Adobe Acrobat for Chrome flaw exposes WhatsApp Web data
North Korean ClickFake campaign targets Web3 professionals
Ransomware on Japan’s cold chain
Fake alert app in Bahrain distributes Android spyware
Two million cars with dealer-installed anti-theft systems are exposed via Bluetooth
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
FalconFlank Exploit Released for CrowdStrike Falcon
Brazilian banking trojan expanding into Portugal
The Adobe Acrobat for Chrome flaw exposes WhatsApp Web data
North Korean ClickFake campaign targets Web3 professionals- Kratos taken down, the phishing kit behind thousands of campaigns per month
- HollowGraph uses Microsoft 365 calendars as a covert C2 channel
- CISA Demonstrates the Defensive Gap in Two Critical Infrastructures
- OpenAI: the models escaped the sandbox and hit Hugging Face
- Google launches CodeMender and Gemini 3.5 Flash Cyber to uncover vulnerabilities
- OT security: the ‘air gap’ is a myth and resilience must be designed
- PR3TACK wants to map threats before attackers use them
- PaperCut: zero-day under attack, emergency patch released











