§Source · SecurityWeek
SecurityWeek
Every dispatch we have aggregated from SecurityWeek.
All dispatches
Loading
§Source · SecurityWeek
Every dispatch we have aggregated from SecurityWeek.
All dispatchesServer Killers group claims a major cyberattack that disrupted Norway's public digital services, causing service outages and data disruption.
Authentication bypasses CVE-2026-61979 and CVE-2026-15981 in miniOrange SAML 2.0 plugin are being exploited to forge admin logins.
Researchers link novel car head unit malware to BadBox botnet, expanding vehicle infection surface for mass abuse.
CISA says CVE-2026-21962 in Oracle WebLogic is actively exploited, enabling remote compromise; immediate patching recommended.
CVE-2026-19478 in GitLab allows unauthenticated modification or deletion of public projects and user data; exploitation observed.
Critical Citrix NetScaler authentication-bypass patches issued; exploitation expected without authentication across gateways and ADCs.
GitLab fixed a critical code injection flaw allowing unauthenticated actors to modify or delete user data and public projects.
CVE-2026-15748 arbitrary file upload bug in a WordPress form plugin lets unauthenticated attackers upload executable files on ~300,000 sites.
Hackers stole names, addresses, phone numbers, Social Security numbers, and financial details from a third-party platform affecting 1.2 million.
An unpatched GeoServer SQL-injection zero-day is being exploited in the wild, potentially enabling remote code execution and data theft.
Miscellaneous security items include Rapid7 layoffs, aviation security research, and industrial refrigeration system weaknesses.
ShinyHunters published stolen personal data for 1.6 million RingCentral users after a July compromise.
Exploit 'ShieldBreak' enables any user to spawn a SYSTEM shell on Windows via a newly released zero-day toolset.
Critical Adobe Commerce vulnerability was targeted and exploited shortly after disclosure, risking customer account takeover.
Critical VMware vCenter flaw (CVE-2026-59310) is being actively exploited to deploy reverse SSH persistence backdoors.
Zoom patches a zero-click annotation vulnerability that could let meeting participants execute code on other attendees' devices.
A Chrome extension removed for stealing AI chats returned to the Web Store and resumed malicious activities — immediate remediation recommended.
Get these articles delivered to your inbox.
Subscribe free