Network Security

Cybersecurity
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
Palo Alto Unit 42 documents Kimwolf v7 using HTTP/2 C2 to mimic legitimate browsing, evade DDoS detection, and expand across Android and IoT devices worldwide.
Cybersecurity
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
A combined heat and power plant in Poland suffered a turbine shutdown and process-water treatment disruption after attackers accessed its cellular ICS network.
CVE Vulnerability Alerts
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
CISA added exploited Progress Kemp LoadMaster command injection CVE-2026-8037 to its KEV catalog after 792 in-the-wild exploitation attempts were documented.
Cybersecurity
4,407 Rockwell PLCs Exposed Online, 22 in Water Cities
A Forescout scan found 4,407 internet-exposed Rockwell PLCs, including 22 in water-industry attack target cities, heightening critical infrastructure risk.
CVE Vulnerability Alerts
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT
Researcher Malcolm Stagg's NatJack technique hijacks TCP sessions and spoofs DNS through NAT table manipulation, affecting Windows Hyper-V and Linux Netfilter.
Cybersecurity
iCloud Private Relay WebKit Bypasses Expose Users’ Real IPs
Researchers Haj Bakry and Mysk found WebKit proxy bypasses in iCloud Private Relay that can expose a user's real IP address to websites and observers.
Cybersecurity
China Launches Probe Into Palo Alto Networks Product Security
China's Cyberspace Administration began a review of Palo Alto Networks products, raising echoes of its Micron ban over critical infrastructure security.
Cybersecurity
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
VulnCheck disclosed a factory-shipped ENDLESSDOORS backdoor in Zbtlink router firmware that lets a remote attacker open an unauthenticated root shell.
CVE Vulnerability Alerts
Cisco Patches Critical SD-WAN, IOS XE, and FMC Flaws
Cisco patched two dozen flaws including critical Catalyst SD-WAN and IOS XE command-injection bugs plus an FMC authentication bypass in a new advisory release.
CVE Vulnerability Alerts
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.