LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host

vulnerability

vulnerability

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions […]

nasacritical

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

A critical vulnerability has been discovered in NASA/JPL's open-source AIT-GUI software, which is used to control spacecraft instruments. The flaw allows unauthenticated attackers to execute arbitrary commands, run server-side scripts, and manipulate command sequences by exploiting a lack of authentication, session checks, and CSRF protection. Researchers confirmed the issue, which has a CVSS score of 9.4, and a fix is available in version 2.5.2.

CVE-2026-73570critical

U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

CISA has added a critical vulnerability in Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-73570, allows unauthenticated remote code execution and is being actively exploited by threat actors. Zimbra released a patch for the vulnerability less than a month before exploitation was confirmed.

vulnerability

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf

vulnerability

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a

vulnerability

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek.

vulnerabilitycritical

Six Maximum-Severity Flaws Found in Cisco Products

Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe. […]

vulnerabilitycritical

Critical Isolated-vm Vulnerability Leads to RCE on Host

The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek.

vulnerabilityhigh

CISA orders feds to patch actively exploited TrueConf Server flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]

CVE-2026-69836critical

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, and connected third-party apps. Tracked as CVE-2026-69836, with the maximum CVSS score of 10.0, the vulnerability was di

vulnerability

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]

breach

SickKids data breach exposes employee and job applicant info

Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]

CVE-2026-19478critical

GitLab Critical GraphQL Flaw Actively Exploited

GitLab has released an emergency patch for a critical vulnerability in its GraphQL API that allows unauthenticated attackers to modify or delete public projects and user data. Researchers from WatchTowr discovered the flaw, tracked as CVE-2026-19478, which has a CVSS score of 9.4 and is reportedly under active exploitation. The vulnerability affects self-managed installations, and users are urged to upgrade to specific patched versions, as older branches will not receive direct fixes.

CVE-2026-73570critical

Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw

CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a critical vulnerability in Zimbra Collaboration Suite tracked as CVE-2026-73570. The flaw allows unauthenticated remote code exec

vulnerability

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: TrueConf Server is an on-premises video conferencing and unified communications platform developed by TrueCon

vulnerability

Microsoft Rolls Out 22 Fresh Security Patches

Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek.

CVE-2026-19490critical

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix has released patches for two critical vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products. The most severe, CVE-2026-19490, is an authentication bypass flaw with a CVSS score of 9.3 that could allow attackers to bypass login checks under specific configuration conditions. A second vulnerability, CVE-2026-19489, is a memory overflow issue with a CVSS score of 8.8 that can lead to denial of service.

cisahigh

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA has issued a directive for immediate patching of critical vulnerabilities affecting TrueConf software. The Head Mare hacktivist group is actively exploiting these flaws to distribute the PhantomCore malware. Organizations using TrueConf are urged to apply the necessary updates to prevent further compromise.

CVE-2026-12569critical

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

The Cl0p ransomware group has claimed responsibility for exploiting a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software, impacting over 40 organizations. The group is using a custom implant for data theft and extortion, demanding payment from victims. Several major companies, including Shell and Philips, are reportedly among the targeted entities, though most have only acknowledged awareness and are investigating.

CVE-2026-19478critical

GitLab Code Injection Vulnerability Actively Exploited

A critical code injection vulnerability in GitLab, identified as CVE-2026-19478, is being actively exploited shortly after its public disclosure. The flaw enables unauthenticated attackers to alter or delete public projects and their data under specific circumstances.

CVE-2026-69836high

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service. It was previously called Azure Active Directory

vulnerability

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

Secure Workload Software has five nasty flaws and even SaaS users have updates to install

supply chain attackhigh

Hackers poison arrayref Rust crate to push infostealer malware

Hackers compromised the maintainer account for the popular Rust crate `arrayref`, injecting malware that executes during the compilation process on developers' systems. This supply-chain attack also affected two other crates, `append-only-vec` and `internment`, within a short timeframe. The malware, disguised as a dependency, attempts to steal credentials from browsers and establish persistence across various operating systems.

vulnerability

N-able Bug Exposes Password Vault Master Keys

The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?

malwarehigh

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More

This week's cybersecurity landscape features several significant threats, including the abuse of legitimate signed drivers for kernel operations, a large-scale cyber espionage campaign by an Iran-based group targeting universities, and malware utilizing DLL sideloading. Additionally, advancements in AI safety are being explored by OpenAI and Google, while a new service, Kriminal AI, offers unfiltered AI responses, raising concerns about misuse. Apple is also modifying its App Tracking Transparency feature in Germany following regulatory scrutiny.

CVE-2026-73570

Hackers Target Zimbra Servers in Active Exploitation Campaign

Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek.

vulnerabilitycritical

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]

vulnerability

JFrog Artifactory Flaws Enable Software Supply Chain Attacks

Two Artifactory flaws allowed attackers to poison package metadata across software repositories

CVE-2026-69414

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection […]

breachcritical

Frequently asked questions about the active threat to Siemens S7 Series PLCs

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. Key Takeaways Unattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future

javascriptcritical

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

A critical vulnerability has been discovered in the isolated-vm Node.js library, allowing sandboxed JavaScript code to escape and potentially execute arbitrary code on the host system. The flaw, found in the ExternalCopy component, enables memory corruption and control-flow hijacking. While the isolation primitive itself remains sound, the C++ binding layer that facilitates data transfer across boundaries was found to be vulnerable. Patches are available in versions 6.2.0 and 7.0.1.

CVE-2026-19489critical

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Citrix has released critical security updates for NetScaler ADC and NetScaler Gateway to address two vulnerabilities. The most severe, CVE-2026-19490 (CVSS 9.3), allows for authentication bypass on specific configurations, including those acting as Gateways or AAA servers with SAML actions. A second flaw, CVE-2026-19489 (CVSS 8.8), is a memory overflow leading to potential denial-of-service when the SIP ALG is enabled.

CVE-2026-73570critical

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

Attackers are actively exploiting a critical vulnerability in Zimbra Collaboration (ZCS) that allows for unauthenticated remote code execution. The flaw, identified as CVE-2026-73570 with a CVSS score of 8.9, stems from improper input sanitization in the SNMP notification processing. Exploitation can lead to the execution of arbitrary operating system commands as the Zimbra user. Zimbra has released version 10.1.20 to patch this vulnerability, and CERT Polska is urging users to check their logs for signs of compromise.

vulnerability

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full […] The post

vulnerabilitycritical

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek.

vulnerability

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]

vulnerabilitycritical

MLflow Vulnerability Exploited for Cloud Credential Theft

The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek.

nfchigh

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Researchers have developed a 'Zombie Card' attack that can enable the use of expired Visa contactless cards for in-store payments. The attack involves a man-in-the-middle relay that rewrites the expiration date read by the point-of-sale terminal, while leaving the card's cryptography intact. This method was successful against some major US banks, though not universally, and highlights potential vulnerabilities in how expiration dates are handled during transactions.

vulnerabilitycritical

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek.

vulnerabilitycritical

CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]

vulnerability

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI

vulnerabilitycritical

Critical Zimbra RCE flaw now actively exploited in attacks

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]

vulnerabilitycritical

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction. The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek.

CVE-2026-19478critical

Critical GitLab Flaw Exploited Shortly After Disclosure

CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data. The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.

CVE-2026-32475critical

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

vulnerabilitycritical

8,539 reasons to rethink how vulnerabilities get patched

The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. Source: Rapi

vulnerabilitycritical

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.

CVE-2024-39943high

Operation CameraSwarm Compromised 14,000+ Dahua Cameras

An exposed operator directory has revealed details of 'Operation CameraSwarm,' a campaign that compromised over 14,000 Dahua cameras, primarily in Ukraine and Russia. The attacker exploited vulnerabilities, including an authentication bypass, and in some cases, leveraged Dahua's cloud relay using only the camera's serial number. The compromised data provided researchers with the attacker's tools, including scanning engines and exploit chains.

CVE-2026-19490critical

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

Overview On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gatew

vulnerability

Exclusive: Linux Foundation's Akrites to Go Live in September

The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects

vulnerabilitycritical

The long tail of Clop’s PTC hack is just beginning to emerge

The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. The post The long tail of Clop’s PTC hack is just beginning to emerge appeared first on CyberScoop.

vulnerabilitycritical

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this Oracle Critical Patch Update, Oracle Fusion Middleware and Oracle

vulnerability

Microsoft fixes known issue causing Windows Defender crashes

Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]

CVE-2026-65400critical

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

vulnerability

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek.

vulnerabilitycritical

Critical RCE flaw in Windows IKE Extension now actively exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...]

vulnerability

943 Patches Rolled Out With Oracle’s August 2026 Security Update

The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Oracle’s August 2026 Security Update appeared first on SecurityWeek.

CVE-2026-33824

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchan

vulnerabilitycritical

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates. Key Takeaways The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates 154 issues (16.3% of all patches) were assigned a critical severity rating Oracle Fusion Middleware received the highest number of patches at 262,

CVE-2026-68820high

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing [