FalconFlank Exploit Released for CrowdStrike Falcon
Security researcher known as Chaotic Eclipse has published a proof-of-concept (PoC) for a zero-day vulnerability dubbed 'FalconFlank' that affects the CrowdStrike Falcon
Zero-day SonicWall SMA 1000 exploited in the wild
SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authen
JFrog Artifactory hit by an authentication bypass exploited immediately after disclosure
JFrog Artifactory, one of the most widely used repository managers in DevOps pipelines and package distribution, has come under scrutiny after the disclosure of CVE-2026-82329. The
McKesson under pressure after a cyber incident and ShinyHunters’ claim
McKesson, the large Texas-based pharmaceutical distributor, has confirmed a security incident that is causing disruptions to its systems. The company said the intrusion involves a
PaperCut: emergency patch 2 closes the exploited RCE chain
PaperCut has released Emergency Patch Release 2 after researchers demonstrated that the first fix could be bypassed against a pre-authentication remote code execution chain that wa
PaperCut: zero-day under attack, emergency patch released
PaperCut Software has confirmed that a zero-day vulnerability in the NG and MF products has already been actively exploited in real-world attacks. The company has released an emerg
PaperCut under attack with an already exploited zero-day
PaperCut has confirmed that a vulnerability in the NG and MF products is being actively exploited in zero-day attacks. The company has released emergency patches for v25 and v26 an
Arrests in Australia for TeamPCP and a massive supply-chain compromise campaign
Australian police have charged two men from Western Australia, accused of being part of the TeamPCP group, at the center of a long-running campaign of software supply chain attacks
CISA Demonstrates the Defensive Gap in Two Critical Infrastructures
CISA has published the results of two red team assessments conducted in parallel against two critical infrastructure organizations. In both environments, the testers were able to a
CISA adds Oracle HTTP Server/WebLogic Proxy Plug-in to KEV catalog for active exploitation
CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog after finding evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Pro

