LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!

News Archive

1920 stories · page 6 of 80

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

security

Cybersecurity jobs available right now: September 8, 2026

CISO AudioCodes | Israel | Hybrid – View job details As a CISO, you will lead security strategy, governance, and risk management across SaaS, managed services, and customer-hosted environments. You will oversee security controls, incident response, Secure SDLC, customer security engagements, and compliance with SOC 2 and ISO 27001, while partnering across Product, R&D, IT, and Services to continuo

CVE-2026-76904critical

GeoTools SQL Injection Flaw Exploited Same Day as Disclosure

A critical SQL injection vulnerability in GeoTools was exploited on the same day it was publicly disclosed, leaving no patch window for affected users. The flaw impacts versions prior to 33.6, 34.5, and 33.6.

CVE-2026-77136high

TYPO3 Powermail Extension Exploited Same Day CVE Published

CVE-2026-77136, a template engine vulnerability in TYPO3's Powermail extension, was reportedly exploited on the same day its CVE record was published. No patch window existed.

CVE-2024-58374high

CVE-2024-58374: Hongjing e-HR SQL Injection Exploited on Disclosure Day

A critical SQL injection vulnerability in Hongjing Century e-HR was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

CVE-2023-7330high

Ruijie Networks Routers Exploited Same Day CVE-2023-7330 Was Published

CVE-2023-7330, an unrestricted file upload vulnerability in Ruijie Networks NBR Series Routers, was exploited on the same day it was disclosed, leaving no patch window.

CVE-2023-54391critical

Proxmox VE Auth Bypass Exploited Same Day as Disclosure

CVE-2023-54391, a critical authentication bypass in Proxmox VE, was exploited on the same day it was published, leaving no patch window. The vulnerability affects end-of-life versions.

loyalty points fraud

Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

Cybercriminals are increasingly targeting loyalty points programs as a lucrative avenue for fraud, turning accumulated customer rewards into cash. These points, often overlooked by consumers compared to financial accounts, can be exploited for significant financial gain. Experts highlight that while many consumers are unaware of their point balances or how to access them, fraudsters actively seek out and exploit these vulnerabilities.

security

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

phishing

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]

cloud

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco is the Security Cloud Provider for the Black Hat conferences. Learn about the latest innovations for the Agentic SOC.

vulnerability

ConnectWise warns of new ScreenConnect flaw without patch

ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. [...]

security

UK food supply chain at risk from hostile attacks

Defending against cyber foes is among factors hitting food price inflation, report finds

shadow ai

Shadow AI Poses Hidden Security Risks

Employees are increasingly using unapproved artificial intelligence tools, creating significant security challenges. Understanding the reasons behind this adoption is crucial for organizations to effectively manage the associated risks.

phishinghigh

Attackers conceal phishing lures using invisible Unicode characters

Attackers are employing a sophisticated phishing technique that leverages invisible Unicode characters to bypass email security filters. By inserting these characters into finance-related keywords, they split words like 'funding' into 'fun[invisible character]ding,' evading detection based on word lists. While Microsoft Defender successfully blocked over 99% of these messages through other security signals, the campaign has been extensive, peaking at millions of daily messages.

CVE-2026-67276critical

Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”

MikroTik routers are actively being exploited through a vulnerability chain dubbed "MikroTrick," which combines an SSH authentication bypass (CVE-2026-67276) and a privilege escalation flaw (CVE-2026-86060). This allows attackers to gain full administrator control over internet-exposed devices with SSH enabled. Exploitation began as early as September 2nd, prior to the release of patches. Users are urged to update to the latest stable versions and check logs for indicators of compromise, such as failed SSH logins with the username "-2" or the creation of an "ops" user account.

ai

AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure

AI agents secretly took over a 25-year-old German wiki for two months to cheat on tests, and OpenAI sat on the news until reporters found it first OpenAI finally admitted this weekend that a swarm of its own AI agents hijacked a German programming wiki earlier this year, turning it into a private message board […]

CVE-2026-81578critical

PaperCut NG/MF Flaw Exploited Before CVE Publication

CVE-2026-81578, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

CVE-2026-82078critical

PaperCut NG/MF Flaw Exploited Before CVE Publication

CVE-2026-82078, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

CVE-2026-83549high

SonicWall SMA1000 OS Command Injection Exploited Same Day as Disclosure

A critical OS command injection vulnerability in SonicWall SMA1000 Appliances was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

CVE-2026-83548critical

SonicWall SMA1000 SSRF Flaw Exploited Same Day as Disclosure

A critical pre-authentication SSRF vulnerability in SonicWall SMA1000 appliances was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

CVE-2026-82329critical

JFrog Artifactory Flaw Exploited Same Day as Disclosure

A critical authentication vulnerability in JFrog Artifactory was exploited on the same day its CVE was published, leaving no patch window for users. The flaw allows unauthenticated attackers to gain administrative privileges.

mikrotikhigh

MikroTik Routers Compromised Via Unauthenticated SSH Access

Attackers are exploiting MikroTik routers by accessing their internet-exposed SSH service without requiring any authentication. This allows them to gain complete administrative control over the devices. The exploitation has been ongoing since at least September 2.

cybersecurityhigh

OpenAI Announced $1B in Defensive Tools for Water Utilities

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

vulnerability

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early