CISA adds cPanel auth bypass and SonicWall SMA buffer overflow to KEV catalog, mandating federal patching.
Latest Security News
Aggregated from vendors, research teams & government advisories
CISA Alerts & Advisories
CISA, FBI, NSA joint advisory on Russian state-sponsored operations targeting critical infrastructure.
Emergency Directive 26-02 requiring enhanced monitoring and mitigations across actively exploited zero-days.
NCSC (UK)
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.
Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it
Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.
Notable CVEs (NVD)
Critical pre-authentication bypass in cPanel & WHM. Exploited in ransomware campaigns since February 2026.
Elevation of privilege in Windows Kerberos KDC. Actively exploited. Patch included in May 2026 update.
Pre-authentication heap-based buffer overflow in SonicWall SMA 1000 series allowing unauthenticated RCE.
SonicWall
SonicWall Capture Labs published their Q1 2026 threat report highlighting 98 new malware variants and 22% increase in ransomware targeting SMBs.
Critical pre-authentication buffer overflow in SMA 1000 series SSLVPN appliances. Update to firmware 12.4.3 immediately.
Network Security Manager update introduces ML-based anomaly detection and automated policy recommendations.
Fortinet
Critical heap-based buffer overflow in FortiOS SSL-VPN pre-authentication. Affects 7.2.x through 7.4.x. Upgrade to 7.4.3+.
New managed SOC service combining AI-driven threat detection with human analysts for mid-market enterprises.
FortiManager 7.6 introduces zero-trust policy templates, improved multi-tenancy, and FortiCNAPP integration.
ESET / WeLiveSecurity
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
Your inbox is an identity system all of its own: whoever owns it may own a lot more
Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience.
Zscaler / ThreatLabz
Zscaler research shows phishing attacks up nearly 50%, with AI tools and phishing kits enabling large-scale campaigns.
ThreatLabz identifies new ransomware group exploiting unpatched vulnerabilities in enterprise collaboration platforms.
Latest platform update introduces AI-driven security posture assessment and automated policy tuning.
The Hacker News
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordina...
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model...
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsof...
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began ...
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list i...
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated...
BleepingComputer
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. [...]
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]
The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. [...]
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. [...]
SecurityWeek
New executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks. The post <a href="https://www.securityweek.com/trump-orders-defense-contractors-to-map-software-suppliers-across...
The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models
The startup will use the investment to accelerate the development of its threat prediction and discovery products. The post Empirical Security Raises $25 Million in Series A Funding appeare
Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville The post <a href="https:...
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C�
Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to
Dark Reading
Gangs moving from encryption to pure data extortion, reducing technical complexity while increasing pressure.
67% of CISOs find CSPM tools overwhelming due to alert fatigue and lack of integration.
Energy, water, and transportation sectors face increasingly sophisticated state-sponsored cyber attacks.