
Attackers Hijack Three Country TLDs to Forge Google Certificates
Google says attackers compromised the .gh, .sl and .as registries, altered DNS records and obtained fraudulent HTTPS certificates for Google

Google says attackers compromised the .gh, .sl and .as registries, altered DNS records and obtained fraudulent HTTPS certificates for Google

SonicWall fixed four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10.0 unauthenticated SSRF in the WorkPlace portal. No exploitation has

An FBI and Secret Service advisory says a Russian initial access broker is using stolen credentials to lock organizations out

Florida, Iowa, Montana and Nebraska sued router maker TP-Link, alleging misleading security claims and concealed China ties. TP-Link calls the

FortiGuard and Nozomi detail Cling, a Linux botnet that hides command traffic in STUN requests and exploits about two dozen

Citrix released emergency patches for CVE-2026-88779, a NetScaler SAML zero-day under active attack that can knock enterprise login gateways offline

Fortinet confirmed active exploitation of a critical FortiMail flaw with no fix shipped for most versions, and CISA added it

Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that attackers are actively exploiting to seize full

WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14

CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.