Attackers are actively exploiting a critical vulnerability in Cisco Secure Firewall Management Center (FMC) to deploy Qilin ransomware, according to recent reports. The flaw, which has not yet been assigned a CVE identifier in the provided information, allows for the deployment of ransomware, indicating a significant risk to affected systems.
In a related development, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog. These include flaws affecting Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler. CISA also updated its catalog with actively exploited vulnerabilities in Microsoft Windows, N-able N-central, and Adobe products.
Google has addressed the seventh actively exploited Chrome zero-day of 2026, highlighting ongoing threats to web browsers. This particular zero-day was reportedly exploited by four distinct nation-state actors within a 12-day period using the same exploit kit.
Another significant vulnerability, CVE-2026-85706 in GitLab, is being actively exploited. This flaw allows for a full file read with a single unauthenticated HTTP request and was reportedly exploited within 24 hours of its discovery.
Microsoft's recent Patch Tuesday was substantial, addressing 974 CVEs. Among these were two zero-day vulnerabilities and 20 wormable bugs, emphasizing the breadth of security issues being patched.
Beyond these specific vulnerabilities, a new fileless Linux rootkit named PoisonedRefresh has been identified. This rootkit injects PHP web shells directly into the memory of F5 BIG-IP APM servers, making detection more challenging.
In other attack news, a UK Council attack has been linked to the mass exploitation of a SonicWall flaw. Additionally, a WeChat worm has been reported that can hijack user accounts without requiring the victim to answer a call.
Researchers have also released ShieldCrash, a proof-of-concept exploit for a Microsoft Defender zero-day vulnerability, under the name Chaotic Eclipse. This indicates potential future threats to Microsoft Defender users.
Finally, a separate incident saw hackers drain $320 million from the Liquid Network, though most of the stolen funds were subsequently returned.






