Resources
SharePoint Flaw Enables Authenticated RCE Despite Spoofing Rating
Andrew Doyle
September 23, 2026
CVE-2026-65660, initially classified by Microsoft as spoofing with CVSS 6.5, enables authenticated remote code execution on SharePoint Server per researcher analysis.
WordPress Patches Comment2Shell Anonymous-to-RCE Attack Chain
Mitchell Langley
September 23, 2026
WordPress patched CVE-2026-93485 (Comment2Shell) in version 7.1.1 on September 17, a flaw allowing anonymous comments to achieve RCE when viewed by administrators.
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
Andrew Doyle
September 21, 2026
CVE-2026-89026 in Issabel Framework under active exploitation allows unauthenticated attackers to execute arbitrary OS commands remotely via hard-coded credentials.
Citrix NetScaler CVE-2026-19490 Exploited Since September 3
Mitchell Langley
September 11, 2026
Critical authentication bypass vulnerability CVE-2026-19490 in Citrix NetScaler has been actively exploited since September 3, enabling unauthenticated attackers to bypass authentication controls.
CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws
Andrew Doyle
September 11, 2026
CISA added three actively exploited vulnerabilities in Cisco, Citrix, and Fortinet products to its KEV catalog on September 10, requiring federal agencies to patch by ...
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
Andrew Doyle
September 11, 2026
Google released Chrome security update on September 9 patching CVE-2026-87491, an out-of-bounds write in V8 engine — the seventh actively exploited Chrome zero-day of 2026.
cPanel Critical RCE Enables Full Server Takeover via Mail Account
Andrew Doyle
September 9, 2026
Critical cPanel vulnerability lets authenticated hosting account holders execute root-level code and take complete control of entire server infrastructure.
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
Andrew Doyle
September 9, 2026
SAP released patches for CVE-2026-44756, a maximum-severity memory corruption flaw enabling unauthenticated remote code execution in SAP kernel systems.
Microsoft Ships Record 974 Security Patches in September Batch
Andrew Doyle
September 9, 2026
Microsoft's September Patch Tuesday delivered 974 security fixes—the largest single batch ever—driven partly by AI-assisted vulnerability discovery tools.
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Andrew Doyle
September 2, 2026
Russian-speaking Aurora ransomware group leveraged Cursor AI coding assistant to conduct hands-on exploitation against 10 targets between April and May 2026.
Weekly Newsletter
Weekly Cybersecurity Newsletter: 14th to 18th August
Andrew Doyle
July 19, 2025
Explore our latest cybersecurity podcast episodes featuring ransomware attacks, phishing campaigns, corporate breaches, legal showdowns, and deep dives into evolving threats and digital defenses.
This Week In Cybersecurity: 23rd June to 27th June
Andrew Doyle
June 30, 2025
News Stories New ‘FileFix’ Attack Exploits Windows File Explorer to Deliver Stealthy Commands Threat actors use the search-ms URI protocol ...
This Week In Cybersecurity: 26th to 30th May, 2025
Andrew Doyle
May 30, 2025
"Cybersecurity threats escalate as ransomware attacks target major organizations, exposing sensitive data and highlighting vulnerabilities in systems across various industries. Stay informed."
This Week In Cybersecurity: 19th to 23rd May, 2025
Andrew Doyle
May 23, 2025
This week, significant cybersecurity incidents include ransomware attacks, data breaches affecting major organizations, and ongoing threats from state-sponsored groups, highlighting vulnerabilities across various sectors.
This Week In Cybersecurity: 21st – 25th April, 2025
Andrew Doyle
April 25, 2025
Targeted malware, ransomware, phishing, and ad fraud hit SK Telecom, Baltimore schools, Google, and more this week—exposing critical data and abusing trusted systems.
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.














