Category: Vulnerabilities
Cloudflare Patches Cross-Tenant Data Leak Bug in Containers Service
A flaw in Cloudflare's shared storage pool let Workers Paid customers recover residual data, including credentials and databases, left behind by other…
Microsoft Pauses KB5002907 After Update Deactivates Perpetual Office Installs
An optional Microsoft 365 update meant to refresh out-of-date installations instead deactivated, and in some cases completely removed, perpetual Office 2016 and…
Two Unpatched Citrix NetScaler Zero-Days Under Active RCE Exploitation
Security firm watchTowr says attackers are actively exploiting two unpatched remote code execution flaws in Citrix NetScaler ADC and Gateway appliances, with…
ShinyHunters Breached Clop’s Own Leak Site via Unpatched Grav CMS Flaw
An unauthenticated path traversal bug in Grav CMS 1.7 let ShinyHunters deface and steal data from Clop's Tor leak site, prompting Clop…
CISA Confirms Active Exploitation of SharePoint and MikroTik RouterOS Flaws
A critical SharePoint code injection bug and a MikroTik RouterOS vulnerability have both been added to CISA's Known Exploited Vulnerabilities catalog after…
CISA Flags Active Exploitation of WSO2 and Adobe Commerce Critical Flaws
CISA has added critical WSO2 and Adobe Commerce vulnerabilities to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 27 to…
Attackers Weaponize Critical WordPress RCE Flaw Within Hours of Patch
CVE-2026-87902, a critical unauthenticated path traversal bug in WordPress core, is under active exploitation just hours after a fix landed in version…
Astrana Health Discloses Data Breach After Social Engineering Attack
Attackers impersonated Astrana Health staff and spoofed the company's phone number to trick employees, gaining access to servers and exfiltrating private and…
New RemControl Android Trojan Hijacks Banking Apps Across Europe and Canada
A new malware-as-a-service platform called RemControl is spreading through fake TVTap IPTV apps, using Accessibility Service abuse and AI-crafted phishing overlays to…
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Remote Code Execution
F5 has fixed a critical zero-day in BIG-IP Access Policy Manager that attackers used to achieve unauthenticated RCE, prompting CISA to order…
Sweden Fines Miljödata $183,000 Over Breach Hitting 2.2 Million Residents
Swedish regulator IMY says the HR software provider failed to vet new software installs and lacked real time intrusion monitoring ahead of…
CISA Orders Federal Agencies to Patch Exploited Zyxel Switch Flaw by Thursday
A stack-based buffer overflow in Zyxel GS1900 series switches is being actively exploited to steal data, prompting CISA to add the bug…