CISA adds Oracle HTTP Server/WebLogic Proxy Plug-in to KEV catalog for active exploitation
CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog after finding evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Pro
Suspected Iran-linked attack takes UK power plant offline
According to press sources cited by Help Net Security and Infosecurity Magazine, a British power plant remained offline for four days in July 2026 because of a cyberattack suspecte
CISA adds four critical vulnerabilities to KEV catalog for active exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming their acti
Brazilian banking trojan expanding into Portugal
A banking trojan born in Brazil is actively spreading in Portugal, taking advantage of the fact that criminals share the same language as their targets and can therefore build more
Iranian attacks against Siemens and Schneider industrial systems
U.S. agencies have warned that Iranian cyber actors are targeting Siemens and Schneider industrial systems used in American environments. The focus on ICS components is significant
Check Point SmartConsole: authentication bypass actively exploited
Check Point has fixed a critical vulnerability in the SmartConsole login process, tracked as CVE-2026-16232, which allows an unauthenticated attacker to obtain an application token
Russian campaign against Zimbra with zero-click exploit and theft of emails and 2FA codes
Several Russia-linked groups exploited an as-yet-unknown vulnerability in Zimbra for months to target government and strategic organizations in the West. The vector was particularl
HollowGraph uses Microsoft 365 calendars as a covert C2 channel
Researchers linked the HollowGraph malware to the Cavern framework after discovering that it uses Microsoft 365 calendars and Microsoft Graph APIs as a hidden command-and-control c
North Korean ClickFake campaign targets Web3 professionals
A new campaign attributed to the North Korean group Famous Chollima has targeted professionals in the Web3 sector with the ClickFix lure to deploy trojans on Windows and macOS. The
Google launches CodeMender and Gemini 3.5 Flash Cyber to uncover vulnerabilities
Google has introduced CodeMender as a managed agent for code security and has paired the initiative with Gemini 3.5 Flash Cyber, a model designed to find, validate, and fix vulnera

