CISA adds cPanel auth bypass and SonicWall SMA buffer overflow to KEV catalog, mandating federal patching.
Latest Security News
Aggregated from vendors, research teams & government advisories
CISA Alerts & Advisories
CISA, FBI, NSA joint advisory on Russian state-sponsored operations targeting critical infrastructure.
Emergency Directive 26-02 requiring enhanced monitoring and mitigations across actively exploited zero-days.
NCSC (UK)
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.
Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it
Notable CVEs (NVD)
Critical pre-authentication bypass in cPanel & WHM. Exploited in ransomware campaigns since February 2026.
Elevation of privilege in Windows Kerberos KDC. Actively exploited. Patch included in May 2026 update.
Pre-authentication heap-based buffer overflow in SonicWall SMA 1000 series allowing unauthenticated RCE.
SonicWall
SonicWall Capture Labs published their Q1 2026 threat report highlighting 98 new malware variants and 22% increase in ransomware targeting SMBs.
Critical pre-authentication buffer overflow in SMA 1000 series SSLVPN appliances. Update to firmware 12.4.3 immediately.
Network Security Manager update introduces ML-based anomaly detection and automated policy recommendations.
Fortinet
Critical heap-based buffer overflow in FortiOS SSL-VPN pre-authentication. Affects 7.2.x through 7.4.x. Upgrade to 7.4.3+.
New managed SOC service combining AI-driven threat detection with human analysts for mid-market enterprises.
FortiManager 7.6 introduces zero-trust policy templates, improved multi-tenancy, and FortiCNAPP integration.
ESET / WeLiveSecurity
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
Your inbox is an identity system all of its own: whoever owns it may own a lot more
Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience.
Zscaler / ThreatLabz
Zscaler research shows phishing attacks up nearly 50%, with AI tools and phishing kits enabling large-scale campaigns.
ThreatLabz identifies new ransomware group exploiting unpatched vulnerabilities in enterprise collaboration platforms.
Latest platform update introduces AI-driven security posture assessment and automated policy tuning.
The Hacker News
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the code...
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The...
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, whic...
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its o...
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader...
Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together seve...
BleepingComputer
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]
Microsoft is impacted by a massive outage affecting Teams and Microsoft 365 services, primarily affecting users in North America. [...]
SecurityWeek
AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead?
Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts. The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared first
The latest investment round brings the total raised by Abstract to nearly $50 million. The post Abstract Raises $25 Million to Expand Composable Security Operations Platform
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips U
Hackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent
Dark Reading
Gangs moving from encryption to pure data extortion, reducing technical complexity while increasing pressure.
67% of CISOs find CSPM tools overwhelming due to alert fatigue and lack of integration.
Energy, water, and transportation sectors face increasingly sophisticated state-sponsored cyber attacks.