Cyber Security
CVE Vulnerability Alerts
Two Nigerians Extradited to US for Sextortion That Killed Two Teens
Gabby Lee
September 1, 2026
Adebola Adekunle and Mudasiru Olawale were extradited from Nigeria on August 31 to face charges in sextortion schemes that killed two U.S. teens.
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Gabby Lee
September 1, 2026
U.S. District Judge Rita Lin ruled Pentagon
Application Security
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
Mitchell Langley
September 1, 2026
METR disclosed two incidents where attackers stole API keys and consumed $600,000 in AI credits through fail-open authentication and targeted probing.
CVE Vulnerability Alerts
Russia-Aligned UAC-0099 Embeds Nuclear Weapon Text to Evade AI Tools
Andrew Doyle
September 1, 2026
Russian threat actor UAC-0099 deployed GuardBreaker technique, inserting safety-sensitive phrases into malware to trip AI security analysis mechanisms.
Application Security
360 Attacks Target Langflow and Rails Flaws Within 72 Hours
Andrew Doyle
September 1, 2026
VulnCheck recorded 360 exploitation attempts targeting CVE-2026-0768 in Langflow and Rails KindaRails2Shell CVE-2026-66066 within 72 hours of disclosure.
Cybersecurity
Five Venezuelan Nationals Plead Guilty to Kansas ATM Jackpotting
Gabby Lee
September 1, 2026
Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy following December 2025 arrests for Tren de Aragua malware operations in Kansas.
Application Security
Cronos Blockchain Halts Network, Restores State After $74M Exploit
Andrew Doyle
September 1, 2026
Cronos validators halted the blockchain and restored chain state after attacker inflated TONIC token price 100x to borrow $74 million in August 31 exploit.
Application Security
JFrog Artifactory CVE-2026-82329 Exploited Days After Disclosure
Andrew Doyle
September 1, 2026
WatchTowr researchers observed attackers exploiting CVE-2026-82329 to mint admin tokens on JFrog Artifactory instances days after August 28 disclosure.
Application Security
WatchGuard Patches Five Critical RCE Flaws in Fireware and Dimension
Andrew Doyle
September 1, 2026
WatchGuard patched five CVSS 9.3 buffer overflow and privilege escalation flaws enabling unauthenticated remote code execution in Fireware and Dimension.
CVE Vulnerability Alerts
TerminalFix Campaign Uses Reverse Tunnels in ClickFix-Style Attacks
Gabby Lee
September 1, 2026
TerminalFix deploys multistage PowerShell attacks incorporating reverse tunnels into victim networks, using ClickFix social engineering to trick users.
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Gabby Lee
August 12, 2026
CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS 10.0 globally.
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Gabby Lee
August 12, 2026
U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
Application Security
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
Gabby Lee
August 12, 2026
CISA adds CVE-2026-72898 Metabase SQL injection flaw to KEV, setting an August 14 patch deadline for federal agencies and urging enterprises to update.
Cybersecurity
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
Gabby Lee
August 12, 2026
CERT-UA attributes a Sandworm-linked UAC-0145 social engineering campaign using fake job interviews and trojanized WireGuard VPN clients against Ukraine.
Cybersecurity
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
Mitchell Langley
August 12, 2026
Palo Alto Unit 42 documents Kimwolf v7 using HTTP/2 C2 to mimic legitimate browsing, evade DDoS detection, and expand across Android and IoT devices worldwide.
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Mitchell Langley
August 12, 2026
CISA confirms ransomware operators exploit a CVSS 9.1 SharePoint Server RCE requiring no authentication and granting administrator access worldwide today.
Cybersecurity
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
Mitchell Langley
August 12, 2026
A combined heat and power plant in Poland suffered a turbine shutdown and process-water treatment disruption after attackers accessed its cellular ICS network.
CVE Vulnerability Alerts
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Mitchell Langley
August 11, 2026
Metabase confirmed an exploited CVSS 10.0 zero-day SQL injection vulnerability that let attackers access customer data at Framework, Tally, and LexisNexis.
Cybersecurity
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
Gabby Lee
August 11, 2026
Attackers who compromised N-able N-central reached managed endpoints and installed Cloudflare Tunnel persistence, prompting the vendor to release Hotfix 2.
CVE Vulnerability Alerts
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
Andrew Doyle
August 11, 2026
CISA added exploited Progress Kemp LoadMaster command injection CVE-2026-8037 to its KEV catalog after 792 in-the-wild exploitation attempts were documented.
Application Security
cPanel Critical RCE Enables Full Server Takeover via Mail Account
Andrew Doyle
September 9, 2026
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Mitchell Langley
September 9, 2026
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Andrew Doyle
September 2, 2026
Cybersecurity
Boston Scientific Cyberattack Disrupts Manufacturing and Shipping
Gabby Lee
September 2, 2026
TOP CYBERSECURITY HEADLINES
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Cybersecurity
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
This Week’s Security Spotlight
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Mitchell Langley
September 9, 2026
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
Mitchell Langley
September 8, 2026
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Gabby Lee
September 1, 2026
Application Security
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
Mitchell Langley
September 1, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Russia-Aligned UAC-0099 Embeds Nuclear Weapon Text to Evade AI Tools
September 1, 2026
Russian threat actor UAC-0099 deployed GuardBreaker technique, inserting safety-sensitive phrases into malware to trip AI security analysis mechanisms.
360 Attacks Target Langflow and Rails Flaws Within 72 Hours
September 1, 2026
VulnCheck recorded 360 exploitation attempts targeting CVE-2026-0768 in Langflow and Rails KindaRails2Shell CVE-2026-66066 within 72 hours of disclosure.
Five Venezuelan Nationals Plead Guilty to Kansas ATM Jackpotting
September 1, 2026
Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy following December 2025 arrests for Tren de Aragua malware operations in Kansas.
Cronos Blockchain Halts Network, Restores State After $74M Exploit
September 1, 2026
Cronos validators halted the blockchain and restored chain state after attacker inflated TONIC token price 100x to borrow $74 million in August 31 exploit.
JFrog Artifactory CVE-2026-82329 Exploited Days After Disclosure
September 1, 2026
WatchTowr researchers observed attackers exploiting CVE-2026-82329 to mint admin tokens on JFrog Artifactory instances days after August 28 disclosure.
WatchGuard Patches Five Critical RCE Flaws in Fireware and Dimension
September 1, 2026
WatchGuard patched five CVSS 9.3 buffer overflow and privilege escalation flaws enabling unauthenticated remote code execution in Fireware and Dimension.
TerminalFix Campaign Uses Reverse Tunnels in ClickFix-Style Attacks
September 1, 2026
TerminalFix deploys multistage PowerShell attacks incorporating reverse tunnels into victim networks, using ClickFix social engineering to trick users.
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
August 12, 2026
CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS 10.0 globally.
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
August 12, 2026
U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
August 12, 2026
CISA adds CVE-2026-72898 Metabase SQL injection flaw to KEV, setting an August 14 patch deadline for federal agencies and urging enterprises to update.
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
August 12, 2026
CERT-UA attributes a Sandworm-linked UAC-0145 social engineering campaign using fake job interviews and trojanized WireGuard VPN clients against Ukraine.
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
August 12, 2026
Palo Alto Unit 42 documents Kimwolf v7 using HTTP/2 C2 to mimic legitimate browsing, evade DDoS detection, and expand across Android and IoT devices worldwide.
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
August 12, 2026
CISA confirms ransomware operators exploit a CVSS 9.1 SharePoint Server RCE requiring no authentication and granting administrator access worldwide today.
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
August 12, 2026
A combined heat and power plant in Poland suffered a turbine shutdown and process-water treatment disruption after attackers accessed its cellular ICS network.
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
August 11, 2026
Metabase confirmed an exploited CVSS 10.0 zero-day SQL injection vulnerability that let attackers access customer data at Framework, Tally, and LexisNexis.
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
August 11, 2026
Attackers who compromised N-able N-central reached managed endpoints and installed Cloudflare Tunnel persistence, prompting the vendor to release Hotfix 2.
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
August 11, 2026
CISA added exploited Progress Kemp LoadMaster command injection CVE-2026-8037 to its KEV catalog after 792 in-the-wild exploitation attempts were documented.
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
August 11, 2026
Varonis and PromptArmor disclosed prompt-injection flaws in Atlassian Rovo that can exfiltrate Jira, Confluence, and SharePoint data from enterprise tenants.
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
August 11, 2026
PortSwigger researcher Gareth Heyes showed email-borne CSS attacks that capture passwords and steal tokens in Outlook, Gmail, Yahoo, and other webmail services.
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
August 11, 2026
Head Mare hacktivists exploited TrueConf servers and replaced client installers with backdoored versions carrying PhantomCore and PhantomGraph backdoors.



































