LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!

News Archive

1923 stories · page 65 of 81

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

ransomwarehigh

Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION

The latest Security Affairs newsletter covers a range of global cybersecurity incidents and trends. Key topics include ransomware extortion, significant cyberattacks on major companies like Odido and a Japanese taxi operator, and the compromise of the AsyncAPI npm organization. The newsletter also highlights new malware strains, exploitation campaigns targeting CMS, and state-sponsored cyber activities from Russia, China, and North Korea.

apthigh

Hackers abuse ViPNet software to target Russian govt agencies

An advanced threat actor, potentially Chinese-speaking, is targeting Russian government and other high-value organizations by abusing the update mechanism of ViPNet, a popular Russian cybersecurity product. The campaign, active since at least May and dubbed HelloNet, involves injecting malicious DLLs into the ViPNet update directory, which then load further malware payloads like proxies, backdoors, and log cleaners. Researchers have low confidence in the attribution due to weak evidence.

malware

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's

CVE-2026-15409critical

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A sophisticated threat actor, tracked as UTA0533, has been exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits, CVE-2026-15409 and CVE-2026-15410, were chained together to achieve arbitrary command execution and gain root access. The actor leveraged these vulnerabilities to deploy custom malware, establish persistence, and potentially exfiltrate sensitive data.

vulnerabilitycritical

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security issue. Cynative: Open-source deep research agent Running a large language model against a live cloud account to hunt for security holes comes w

CVE-2026-63030critical

Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default

vulnerability

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]

opensslhigh

OpenSSL Vulnerability Allows Memory Exhaustion via 11-Byte Payload

Okta's Red Team has identified a denial-of-service vulnerability in OpenSSL named HollowByte. A remote, unauthenticated attacker can exploit this flaw using an 11-byte payload to trigger excessive memory allocation on the server before the TLS handshake completes, leading to a denial of service. The vulnerability stems from OpenSSL's trust in the declared message size, which allows for large memory allocations based on untrusted input, and the issue is compounded by heap fragmentation preventing memory reuse.

vulnerabilitycritical

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]

CVE-2026-60137high

Two High-Severity WordPress Vulnerabilities Require Immediate Patching

WordPress version 6.9 has been impacted by two significant security flaws. One vulnerability allows for SQL injection, while the other, a REST API issue, could lead to remote code execution. Both have been addressed in the latest security release, version 7.0.2.

malwarehigh

Microsoft Warns of Increased ACR Stealer Malware Attacks

Microsoft has reported a significant increase in attacks leveraging the ACR Stealer malware. This malicious software targets enterprise customers, aiming to pilfer sensitive information such as stored browser passwords, authentication tokens, and important documents.

malwarehigh

China-Linked Daxin Malware Active on Manufacturer's Network Since 2013

Researchers have discovered the China-linked Daxin rootkit and a new Stupig backdoor still active on the network of a Taiwanese subsidiary of a high-tech manufacturer. Evidence suggests the intrusion dates back to 2013, meaning it remained undetected for thirteen years. Daxin, a Windows kernel-mode rootkit, employs advanced techniques to communicate within secured networks and hide its traffic.

CVE-2026-25089critical

CISA Adds Fortinet and Microsoft Flaws to Exploited Vulnerabilities List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added critical vulnerabilities affecting Fortinet FortiSandbox and Microsoft SharePoint to its Known Exploited Vulnerabilities catalog. The flaws include OS command injection in FortiSandbox and a deserialization vulnerability in SharePoint that allows for remote code execution without authentication. Microsoft has confirmed active exploitation of the SharePoint flaw.

breach

Your Period Tracker Is (Probably) Spying on You

Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.

ai

Prompt Injection Attacks Disrupt AI Hacking Agents

New "context bombing" techniques are being used to thwart malicious AI agents. These methods trick the AI into shutting down by feeding it misleading information, preventing it from carrying out harmful actions.

north koreahigh

North Korean hackers use fake coding interviews to steal developer credentials

Elastic Security Labs has identified a new campaign by North Korean threat actors, dubbed 'Contagious Interview,' targeting software developers. The attackers use fake job postings and coding challenges, embedding malware within SVG files using steganography. Successful execution of these projects leads to the deployment of a multi-stage payload designed to steal credentials, cryptocurrency, and provide remote access.

android

Gemini AI Flaw Lets Strangers Message From Locked Android Phones

A vulnerability has been discovered in Google's Gemini AI assistant for Android devices. This flaw allows unauthorized individuals to send messages from a user's locked phone. The issue potentially exposes users to misuse of their communication channels.

CVE-2026-63030critical

Critical RCE Vulnerability in WordPress Core Affects Millions of Sites

A critical unauthenticated remote code execution vulnerability has been discovered in WordPress Core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The flaw, identified by Searchlight Cyber, allows attackers to execute code via the REST API batch endpoint without needing any user interaction or valid account. While exploit details are not yet public, the widespread use of WordPress makes this a significant risk, and urgent patching is recommended.

data breachhigh

Ernst & Young Data Breach Linked to Compromised Third-Party Support System

Ernst & Young (EY) has reported a data breach stemming from a compromised third-party IT support ticket system. The attackers gained access to documents containing client tax information that were stored within the platform. EY detected suspicious activity on April 23rd and has engaged cybersecurity experts to investigate the incident, confirming that unauthorized access has ceased.

CVE-2026-60137critical

Cloudflare WAF Shields WordPress From Critical RCE and SQL Injection Flaws

Cloudflare has released new Web Application Firewall (WAF) rules to protect WordPress sites from two severe vulnerabilities. These flaws include an unauthenticated remote code execution (RCE) bug in the REST API and a related SQL injection vulnerability, affecting specific versions of WordPress. While Cloudflare's WAF provides immediate protection, users are strongly advised to update their WordPress installations to the patched versions released by the WordPress security team.

wordpresscritical

WordPress Core Flaw Allows Unauthenticated Code Execution

A critical vulnerability in WordPress core allows unauthenticated attackers to execute arbitrary code on affected websites. The flaw, discovered by Adam Kues of Searchlight Cyber, impacted all sites running versions 6.9 and 7.0. WordPress has since released patches 6.9.5 and 7.0.2, and has enabled forced updates to protect all sites.

cybersecurityhigh

Abbott Investigates Two Cyber Incidents Amid Extortion Claims

Abbott Laboratories is looking into two distinct cybersecurity events. One incident involved unauthorized access to internal legacy systems within its Cancer Diagnostics business. Separately, the company is investigating claims that its LabCentral portal was breached and data was exfiltrated.

openssl

OpenSSL Flaw Allows Denial-of-Service via Small TLS Requests

A denial-of-service vulnerability in OpenSSL, dubbed HollowByte, can be triggered by sending an 11-byte TLS request. This request causes unpatched servers, particularly those using glibc, to allocate up to 131 KB of memory that remains unavailable until the server process is restarted. The fix was released in June without specific disclosure.

ransomwarecritical

Inc Ransomware Exploits SonicWall SMA Zero-Days

The Inc ransomware group is actively exploiting two zero-day vulnerabilities in SonicWall's Secure Mobile Access (SMA) appliances. Successful exploitation grants attackers root-level control over the affected devices, enabling further malicious activities.