CISA added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities Catalog after active exploitation was observed.
CISA has included two actively exploited TrueConf Server vulnerabilities in its Known Exploited Vulnerabilities Catalog, emphasizing critical risks to federal agencies and beyond.
Citrix has patched critical authentication bypass vulnerabilities affecting NetScaler ADC and Gateway, impacting specific FIPS and NDcPP builds used on gateway and AAA servers.
Healthtech firm CareCloud disclosed a data breach impacting over 3.7 million patients, exposing sensitive healthcare information.
CISA warns of active exploitation of a critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions, enabling attacker code execution without user interaction.
CISA confirms ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability, posing increased risk to enterprise environments.
Two medium-to-high severity vulnerabilities in Johnson Controls Airwall could allow attackers to decrypt sensitive data and read arbitrary files, impacting critical infrastructure security.
The ShinyHunters group breached RingCentral in July, compromising personal data of 1.6 million user accounts.
Microsoft Threat Intelligence analyzes DeadLock ransomware, a Rust-based encryptor that employs decentralized victim communication and negotiation infrastructure alongside double extortion tactics.
LexisNexis took down several services after detecting unusual activity on servers managed by a third-party vendor, raising concerns about potential data breaches.
Gunra ransomware, a double-extortion RaaS exploiting VPN and RDP vulnerabilities, threatens government and critical infrastructure with data encryption and leaks.
The North Carolina Ports Authority confirmed a cyberattack on IT systems at multiple ports causing operational delays and highlighting risks to critical infrastructure.
Healthcare software provider Unlimited Technology Systems disclosed an October 2025 breach impacting over 3.8 million individuals and sensitive healthcare data.
A compromise affecting the Keyv and Cacheable npm packages is leading to reconsideration of token revocation policies due to an active malware that triggers upon premature token revocation.
A high-severity vulnerability in Thermo Fisher Applied Biosystems Genetic Analyzers allows modification of DNA data output files, risking inaccurate test results in healthcare settings.
Attackers use vishing via Microsoft Teams to impersonate IT support and deploy Chaos ransomware targeting organizations in North America through social engineering.
Cisco disclosed a high-severity zero-day vulnerability in its Secure Firewall Management Center involving static credentials, actively exploited to gain unauthorized access.
A coordinated cyberattack targeted operational technology at over 30 Minnesota community water systems in late July, causing outages and communication disruptions.
Broadcom published updates for critical VMware vulnerabilities in ESX, vCenter, Workstation, and Fusion enabling authentication bypass and VM escape with high severity.
A zero-day remote code execution vulnerability in the FastJson Java library is actively exploited by hackers against US organizations, posing a critical threat to enterprise applications.
Iranian state-backed group Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers in attacks across the Middle East, Africa, and South Asia, enhancing stealth and covert activity.
Attackers are exploiting a critical remote code execution vulnerability in Fastjson 1.x used in Spring Boot applications, enabling unauthenticated code execution with Java process privileges and no patch currently available.
Swiss rail manufacturer Stadler Rail faced a ransomware attack by the Everest gang targeting a shared supplier data exchange platform, refusing a $12.3 million ransom demand.
The Anubis ransomware group has claimed responsibility for a cyberattack on Coca-Cola's Fairlife brand and threatened to leak stolen data if ransom demands are not met.
A critical authentication bypass vulnerability in Tycon Systems TPDIN-Monitor-WEB2 allows unauthenticated attackers full administrative control, risking critical infrastructure disruptions.
A critical vulnerability in WordPress core enables unauthenticated attackers to execute code on default installations, prompting urgent patch releases.
Two hackers were sentenced for their 2024 attack on Transport for London, which disrupted 148 systems and forced a password reset for 27,000 employees, causing significant operational and financial impact.
US prosecutors charged three Russian nationals for operating a bulletproof hosting service that enabled ransomware gangs causing over $62 million in damages globally.
SAP released updates fixing a critical CVSS 9.9 out-of-bounds write vulnerability in NetWeaver ABAP that may allow authenticated attackers to corrupt memory and manipulate data.
CISA warns that remote code execution vulnerabilities are actively exploited in Joomla iCagenda and Balbooa Forms extensions through arbitrary file uploads, risking full compromise of affected sites.
Progress Software advises ShareFile customers to shut down Windows servers running Storage Zone Controllers due to a credible security threat, disabling account access as a precaution.