Fake alert app in Bahrain distributes Android spyware
A malicious campaign exploited fake sites imitating Google Play to distribute a fake alert app in Bahrain, in the context of tensions and Iranian missile launches. According to ana
Ransomware on Japan’s cold chain
A ransomware attack hit a Japanese food logistics company, causing delays and disruptions in the distribution chain for frozen products to thousands of customers. Among those affec
Ubuntu snap-confine: the race condition that leads to local root
Qualys disclosed CVE-2026-8933, a high-severity vulnerability in Ubuntu’s snap-confine component that allows an unprivileged local user to gain root privileges. The flaw affe
The Adobe Acrobat for Chrome flaw exposes WhatsApp Web data
Adobe has fixed CVE-2026-48294, a chain of vulnerabilities in its Acrobat extension for Chrome that allowed a malicious site to silently read data from an open WhatsApp Web tab. Gu
Kratos taken down, the phishing kit behind thousands of campaigns per month
German and US law enforcement dismantled Kratos’s infrastructure, a phishing-as-a-service platform considered among the most widely used in the world. The operation was led by th
OpenAI: the models escaped the sandbox and hit Hugging Face
OpenAI admitted an unprecedented security incident during an internal evaluation: some of its models managed to break out of the test sandbox and reach the Internet. According to r
Active exploit on SharePoint CVE-2026-50522 after Patch Tuesday
Microsoft SharePoint has come under attack following the publication of a public proof-of-concept for CVE-2026-50522, a critical deserialization flaw that can lead to remote code e
ServiceNow AI Platform CVE-2026-6875: Unauthenticated RCE Already Exploited
The CVE-2026-6875 vulnerability in the ServiceNow AI Platform allows an unauthenticated attacker to execute remote code on self-hosted instances. Searchlight Cyber disclosed it on
WordPress wp2shell: the exploit chain fueling mass scanning
Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, have been combined into the chain known as wp2shell, capable of going from an unauthenticated request all
Qilin exploits CVE-2026-0257 in PAN-OS GlobalProtect to breach VPNs
The Qilin ransomware operation is abusing CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, to gain unauthorized access to corporate networks. The flaw

