CISA adds cPanel auth bypass and SonicWall SMA buffer overflow to KEV catalog, mandating federal patching.
Latest Security News
Aggregated from vendors, research teams & government advisories
CISA Alerts & Advisories
CISA, FBI, NSA joint advisory on Russian state-sponsored operations targeting critical infrastructure.
Emergency Directive 26-02 requiring enhanced monitoring and mitigations across actively exploited zero-days.
NCSC (UK)
Owners of operational technology encouraged to address avoidable vulnerabilities, and build long-term cyber resilience.
A statement from Ollie Whitehouse, Chief Technology Officer at the NCSC, on AI security following recent incidents.
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
Notable CVEs (NVD)
Critical pre-authentication bypass in cPanel & WHM. Exploited in ransomware campaigns since February 2026.
Elevation of privilege in Windows Kerberos KDC. Actively exploited. Patch included in May 2026 update.
Pre-authentication heap-based buffer overflow in SonicWall SMA 1000 series allowing unauthenticated RCE.
SonicWall
SonicWall Capture Labs published their Q1 2026 threat report highlighting 98 new malware variants and 22% increase in ransomware targeting SMBs.
Critical pre-authentication buffer overflow in SMA 1000 series SSLVPN appliances. Update to firmware 12.4.3 immediately.
Network Security Manager update introduces ML-based anomaly detection and automated policy recommendations.
Fortinet
Critical heap-based buffer overflow in FortiOS SSL-VPN pre-authentication. Affects 7.2.x through 7.4.x. Upgrade to 7.4.3+.
New managed SOC service combining AI-driven threat detection with human analysts for mid-market enterprises.
FortiManager 7.6 introduces zero-trust policy templates, improved multi-tenancy, and FortiCNAPP integration.
ESET / WeLiveSecurity
Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
Zscaler / ThreatLabz
Zscaler research shows phishing attacks up nearly 50%, with AI tools and phishing kits enabling large-scale campaigns.
ThreatLabz identifies new ransomware group exploiting unpatched vulnerabilities in enterprise collaboration platforms.
Latest platform update introduces AI-driven security posture assessment and automated policy tuning.
The Hacker News
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lu...
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logica...
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug ...
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Supe...
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what th...
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome'...
BleepingComputer
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries wit...
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]
SecurityWeek
Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post <a href="https://www.securityweek.com/in-other-news-microsofts-cloud-pa...
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on
The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The post <a href="https://www.securityweek.com/openai-pledges-1-billion-to-bring-frontier-ai-to-critic...
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appe
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old P
Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access. The post Catch Raises $5 Million for AI Executiv
Dark Reading
Gangs moving from encryption to pure data extortion, reducing technical complexity while increasing pressure.
67% of CISOs find CSPM tools overwhelming due to alert fatigue and lack of integration.
Energy, water, and transportation sectors face increasingly sophisticated state-sponsored cyber attacks.