Cybersecurity

Cybersecurity
Multiple Groups Exploit Critical FortiSandbox Flaws Across 200 Countries
Multiple sources confirm active exploitation of CVE-2026-25089 and CVE-2026-39813 against FortiSandbox, with credentials compiled for tens of thousands of appliances.
Cybersecurity
Kodak Confirms Data Breach After ShinyHunters Sets Leak Deadline
Kodak confirms a data breach after the ShinyHunters hackgroup claimed 2.2 million records exfiltrated, with the company asserting no threat to current operations.
F5 Emergency Patch: Critical NGINX Unauthenticated RCE Hits 40 Percent of Web Servers
Cybersecurity
F5 Emergency Patch: Critical NGINX Unauthenticated RCE Hits 40 Percent of Web Servers
F5 released emergency patches for NGINX enabling unauthenticated RCE across 40 percent of web servers worldwide today in an accelerated disclosure window.
Atlassian and Splunk Patch Critical Flaws Splunk AI Toolkit RCE, Atlassian Dependencies
Cybersecurity
Atlassian and Splunk Patch Critical Flaws: Splunk AI Toolkit RCE, Atlassian Dependencies
Atlassian and Splunk emergency patches include an OS command injection in Splunk AI Toolkit plus dozens of Atlassian Server dependency flaws
Cybersecurity
Critical Command Execution Vulnerability Patched in Cisco ISE
Cisco patched a critical command execution vulnerability in its Identity Services Engine where insufficient input validation enabled root-level system access.
Cybersecurity
Rokarolla Android Banking Trojan Targets 217 Banking and Crypto Apps
The Rokarolla Android banking trojan evolved beyond credential theft with a 137-command C2 framework targeting 217 banking and cryptocurrency applications.
Cybersecurity
Phantom Stealer Fileless Malware Targets Browser Credentials in Memory
Researchers identified Phantom Stealer as a new fileless credential stealer targeting all browsers via in-memory execution and anti-analysis techniques.
Cybersecurity
INC Ransomware Targets Healthcare, Education, and Local Government
Investigation reveals INC ransomware achieves consistent revenue by targeting healthcare, education, and local government with rapid encryption and data exfiltration.
Cybersecurity
ClickFix Campaign Linked to Vice Society Uses Compromised WordPress Sites
A malware campaign using Lorem Ipsum lures pivots to ClickFix delivery through compromised WordPress sites, with research suggesting possible links to Vice Society.
Cybersecurity
FortiBleed Compromises 74K Fortinet Firewall Credentials Worldwide
FortiBleed exposes verified Fortinet FortiGate VPN credentials for 74K devices across 194 countries, covering major corporations and a Turkish NATO contractor.