CVE-2026-21589: Critical Atlassian File Access
CVE-2026-21589: Critical Atlassian File Access Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file-access vulnerability affecting eight self-hosted products. The flaw car...
CVE-2026-88779: Citrix NetScaler Zero-Day
CVE-2026-88779: Citrix NetScaler Zero-Day Citrix has patched CVE-2026-88779, a high-severity NetScaler vulnerability that was exploited as a zero-day before fixes became available. The memory overflow...
CVE-2026-90970: GitLab AI Gateway RCE
CVE-2026-90970: GitLab AI Gateway RCE GitLab has patched CVE-2026-90970, a critical vulnerability in the Self-Hosted AI Gateway that can allow an authenticated user with Duo Agent Platform access to e...
FortiMail Zero-Day Under Active Exploitation
FortiMail Zero-Day Under Active Exploitation Fortinet has confirmed that CVE-2026-104286, a critical path traversal flaw in FortiMail, is being exploited in zero-day attacks, and CISA added it to the ...
TeamViewer Fixes Five Remote Access Flaws
TeamViewer Fixes Five Remote Access Flaws TeamViewer has patched five high-severity vulnerabilities in its Full Client and Host applications for Windows, Linux, and macOS. The flaws include local priv...
CVE-2026-76504: Cisco SD-WAN Flaw Exploited
CVE-2026-76504: Cisco SD-WAN Flaw Exploited Cisco has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Catalyst SD-WAN Manager, formerly known as vManage. The flaw allows an...
CVE-2026-86950: Apple CoreGraphics Zero-Day
CVE-2026-86950: Apple CoreGraphics Zero-Day Apple has issued an urgent security patch for CVE-2026-86950, a critical zero-day out-of-bounds write vulnerability in CoreGraphics that enables arbitrary c...
Citrix NetScaler Zero-Days FAQ: CVE-2026-88771 & 88772
Citrix NetScaler Zero-Days FAQ: CVE-2026-88771 & 88772 [Update] October 7, 2026: “SOCRadar Analysis Uncovers NetScaler C2.” [Update] September 30, 2026: “Pre-Disclosure Exploitation of CVE-2026-8...
Operation Talked: A Russia-Linked Cyber Espionage Campaign Targeting U...
Operation Talked: A Russia-Linked Cyber Espionage Campaign Targeting Ukraine’s Defense Industry TL;DR: OPERATION TALKED is an ongoing Russia-linked espionage campaign, exposed after the actor left the...
Roundcube SQLi (CVE-2026-48842) Exploited
Roundcube SQLi (CVE-2026-48842) Exploited A pre-authentication SQL injection vulnerability in Roundcube Webmail is reportedly being exploited in the wild months after patches became available. Tracked...
Check Point Pre-Auth Flaws Under Attack
Check Point Pre-Auth Flaws Under Attack Check Point has warned that two critical, pre-authentication vulnerabilities affecting its security products are being actively exploited. CVE-2026-85102 affect...
CVE-2026-94127: F5 BIG-IP APM RCE Under Active Exploitation
CVE-2026-94127: F5 BIG-IP APM RCE Under Active Exploitation F5 has released emergency engineering hotfixes for CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager (AP...
ShinyHunters Claims Access to FBI Systems
ShinyHunters Claims Access to FBI Systems Days after hijacking Clop’s Dark Web leak site, ShinyHunters claims it breached the FBI, defaced part of its recruitment website, and stole sensitive informat...
CVE-2026-87902 in WordPress Enables Conditional RCE
CVE-2026-87902 in WordPress Enables Conditional RCE Security updates released for WordPress address CVE-2026-87902, a severe unauthenticated path traversal flaw within its page-template resolution mec...
Berlin Data Leak: What Rhysida Published, and What Is Still Unresolved
Berlin Data Leak: What Rhysida Published, and What Is Still Unresolved This post consolidates what has been confirmed by the State of Berlin, what remains the threat actor’s own claim, and what the pu...
August 2026: GTA VI Leak, Keyv & Carhartt Breaches
August 2026: GTA VI Leak, Keyv & Carhartt Breaches August 2026 brought a wide mix of cyber incidents, from large-scale data breaches affecting millions of people to software supply chain attacks t...
Click2Shell: WordPress Flaw Enables RCE Chain
Click2Shell: WordPress Flaw Enables RCE Chain Click2Shell is a vulnerability in WordPress Core that allows a logged-in administrator’s browser to be manipulated into installing and previewing a theme ...
Clop Hack: ShinyHunters Hijacks Data Leak Site
Clop Hack: ShinyHunters Hijacks Data Leak Site [Update] September 23, 2026: ShinyHunters Alleges Breach of the FBI ShinyHunters has turned the tables on rival cybercrime operation Clop (a.k.a. Cl0p), ...
CVE-2026-91843: Check Point Root RCE
CVE-2026-91843: Check Point Root RCE Check Point has patched CVE-2026-91843, a critical stack-based buffer overflow flaw in the login process of its Security Management and Log Server products. If exp...
CVE-2026-76460: Cisco ISE Flaw Actively Exploited
CVE-2026-76460: Cisco ISE Flaw Actively Exploited CVE-2026-76460 represents a critical security flaw in Cisco’s Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Because the...
