Resources
Atlassian Fixes Critical CVE-2026-21589 in Eight Data Center Products
Andrew Doyle
October 6, 2026
Atlassian disclosed CVE-2026-21589, a CVSS 9.3 path traversal flaw that lets unauthenticated attackers read web-root files in eight Data Center products.
ClingSTUN Botnet Abuses STUN Protocol for C2, Exploits Dozens of Flaws
Mitchell Langley
October 6, 2026
FortiGuard and Nozomi detail Cling, a Linux botnet that hides command traffic in STUN requests and exploits about two dozen router and IoT vulnerabilities.
Critical FortiMail Zero-Day Exploited With No Patch Yet
Mitchell Langley
October 2, 2026
Fortinet confirmed active exploitation of a critical FortiMail flaw with no fix shipped for most versions, and CISA added it to its exploited list.
Kiteworks Patches Second Max-Severity Flaw in a Week
Andrew Doyle
October 2, 2026
Kiteworks patched a maximum-severity code injection flaw found through its bug bounty program, marking its second critical disclosure in roughly a week.
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
Mitchell Langley
October 1, 2026
Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that attackers are actively exploiting to seize full admin control.
TeamViewer Patches Critical Access-Control Bypass Flaw
Andrew Doyle
October 1, 2026
TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users to update immediately.
WatchGuard Patches Critical Root Code Execution Flaw
Gabby Lee
October 1, 2026
WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14 other bugs in the same ...
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
Gabby Lee
October 1, 2026
CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash the device remotely.
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
Gabby Lee
October 1, 2026
OpenSSL patched a high-severity DTLS flaw that can expose unencrypted heap memory or crash affected software running its widely used cryptographic library.
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Andrew Doyle
October 1, 2026
Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of remote code execution.
Weekly Newsletter
Weekly Cybersecurity Newsletter: 14th to 18th August
Andrew Doyle
July 19, 2025
Explore our latest cybersecurity podcast episodes featuring ransomware attacks, phishing campaigns, corporate breaches, legal showdowns, and deep dives into evolving threats and digital defenses.
This Week In Cybersecurity: 23rd June to 27th June
Andrew Doyle
June 30, 2025
News Stories New ‘FileFix’ Attack Exploits Windows File Explorer to Deliver Stealthy Commands Threat actors use the search-ms URI protocol ...
This Week In Cybersecurity: 26th to 30th May, 2025
Andrew Doyle
May 30, 2025
"Cybersecurity threats escalate as ransomware attacks target major organizations, exposing sensitive data and highlighting vulnerabilities in systems across various industries. Stay informed."
This Week In Cybersecurity: 19th to 23rd May, 2025
Andrew Doyle
May 23, 2025
This week, significant cybersecurity incidents include ransomware attacks, data breaches affecting major organizations, and ongoing threats from state-sponsored groups, highlighting vulnerabilities across various sectors.
This Week In Cybersecurity: 21st – 25th April, 2025
Andrew Doyle
April 25, 2025
Targeted malware, ransomware, phishing, and ad fraud hit SK Telecom, Baltimore schools, Google, and more this week—exposing critical data and abusing trusted systems.
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.














