Resources
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
Gabby Lee
September 30, 2026
Attackers exploited two Citrix NetScaler zero-days to plant custom WHIPSHOT and SLAPSHOT malware, hitting government, financial, and legal-sector networks.
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
Mitchell Langley
September 25, 2026
Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in May.
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
Mitchell Langley
September 25, 2026
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
Mitchell Langley
September 25, 2026
Threat actors began exploiting CVE-2026-87902, a critical unauthenticated RCE flaw in WordPress core, within hours of public disclosure on September 24.
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities
Mitchell Langley
September 25, 2026
SolarWinds released patches for CVE-2026-28324 and CVE-2026-28325, two critical unauthenticated RCE flaws in Observability Self-Hosted platform.
Check Point Zero-Day Exploited in July, Patched September 22
Gabby Lee
September 23, 2026
Check Point disclosed CVE-2026-93616, a zero-day exploited July 23 allowing unauthenticated script execution on Security Management Servers, and released a patch.
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
Mitchell Langley
September 23, 2026
CVE-2026-90898 (CVSS 9.8) enables unauthenticated remote code execution on Bifrost AI gateway with a single HTTP request. Fixed in version 2.1.0.
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Mitchell Langley
September 23, 2026
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.
Arista VeloCloud CVSS 10.0 Flaw Under Active Exploitation
Andrew Doyle
September 23, 2026
CVE-2026-93952 (CVSS 10.0) in on-premises VeloCloud Orchestrator under active exploit. Unauthenticated attackers access privileged internal functions.
Linux KVM Flaw on ARM64 Exposes Host Memory to Guest VMs
Gabby Lee
September 23, 2026
CVE-2026-89775 in Linux kernel KVM for ARM64 processors exposes freed host memory to guest VMs, enabling guest-to-host privilege escalation when nested virtualization is enabled.
Weekly Newsletter
Weekly Cybersecurity Newsletter: 14th to 18th August
Andrew Doyle
July 19, 2025
Explore our latest cybersecurity podcast episodes featuring ransomware attacks, phishing campaigns, corporate breaches, legal showdowns, and deep dives into evolving threats and digital defenses.
This Week In Cybersecurity: 23rd June to 27th June
Andrew Doyle
June 30, 2025
News Stories New ‘FileFix’ Attack Exploits Windows File Explorer to Deliver Stealthy Commands Threat actors use the search-ms URI protocol ...
This Week In Cybersecurity: 26th to 30th May, 2025
Andrew Doyle
May 30, 2025
"Cybersecurity threats escalate as ransomware attacks target major organizations, exposing sensitive data and highlighting vulnerabilities in systems across various industries. Stay informed."
This Week In Cybersecurity: 19th to 23rd May, 2025
Andrew Doyle
May 23, 2025
This week, significant cybersecurity incidents include ransomware attacks, data breaches affecting major organizations, and ongoing threats from state-sponsored groups, highlighting vulnerabilities across various sectors.
This Week In Cybersecurity: 21st – 25th April, 2025
Andrew Doyle
April 25, 2025
Targeted malware, ransomware, phishing, and ad fraud hit SK Telecom, Baltimore schools, Google, and more this week—exposing critical data and abusing trusted systems.
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.














