MikroTik RouterOS Attack Chain Hijacks Devices
September 7, 2026 Threat actors are actively exploiting a chain of two critical vulnerabilities in MikroTik routers. The attack, dubbed “MikroTrick,” allows hackers to bypass SSH authentication and escalate privileges to gain full administrative control…
StyleSmuggler Magento and Adobe Commerce Zero-Day
September 06, 2026 Attackers are actively exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in. Dutch e-commerce security company Sansec…
IDScan Data Breach Exposes Driver’s Licenses in Dark-Web
September 6, 2026 Identity verification company IDScan is facing multiple lawsuits after hackers allegedly breached its systems and offered more than 153 million U.S. and Canadian driver’s licenses for sale on a dark-web identity theft service…
Critical Citrix NetScaler Authentication Bypass CVE Under Active Exploitation
September 5, 2026 Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway, following the public release of proof-of-concept exploit code on September 4, 2026. The flaw, tracked as…
Malicious Terraform Modules Steal Cloud Credentials via Cloudflare Infrastructure
September 4, 2026 Threat actors compromised the Cloudflare infrastructure behind Coder’s module registry and served malicious Terraform modules to developers. Consequently, organizations using the popular self-hosted development platform may have…
Critical HPE ArubaOS-CX RCE CVE: Unauthenticated Remote Code Execution in Enterprise Switches
September 3, 2026 HPE has patched a critical unauthenticated remote code execution vulnerability in ArubaOS-CX, the network operating system powering its enterprise-grade switches. Tracked as CVE-2026-73749, the flaw could allow remote attackers to take…
Sangoma Switchvox SQL Injection Under Active Exploitation
Threat actors are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, an enterprise VoIP management platform. The flaw allows remote code execution without any credentials, and researchers have observed…
SonicWall SMA1000 Zero-Day Flaws Under Active Exploitation
Threat actors are actively chaining two critical zero-day vulnerabilities in SonicWall SMA1000 remote access appliances to achieve remote code execution on enterprise devices. The vulnerabilities, tracked as CVE-2026-83548 and CVE-2026-83549, affect…
Fire Ant Espionage Campaign Hijacks Cisco Routers
August 31, 2026 A China-nexus cyber espionage actor tracked as Fire Ant has evolved beyond hypervisor compromise to hijack Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Consequently, the group turns trusted network…
Rhysida Ransomware Attack on Berlin Government
August 31, 2026 Berlin’s state government has confirmed that it is the target of a major ransomware and data extortion campaign. Consequently, threat actors claiming affiliation with the Rhysida ransomware group have added the German capital to…