WaterPlum North Korean Hackers Infect 30,000 Devices and Steal $10.7 Million in Cryptocurrency
September 19, 2026 A joint law enforcement advisory from the United States, Japan, Australia, and Germany warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide. The group also transferred more than $10.7…
Passkey-Themed Phishing Attacks Target Microsoft 365
September 11, 2026 Microsoft has confirmed that threat actors linked to the ShinyHunters and Helix extortion gangs are conducting sophisticated passkey-themed phishing campaigns that compromise corporate Microsoft 365 accounts and steal sensitive data.…
Critical Path Traversal Flaw Under Active Exploitation
September 11, 2026 On September 10, 2026, GitLab disclosed CVE-2026-85706, a maximum-severity path traversal vulnerability in its repository commits API. The flaw carries a CVSS score of 10.0 and allows unauthenticated attackers to read arbitrary files…
Cisco Critical FMC Authentication Bypass Confirmed Under Active Exploitation
September 10, 2026 Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. Furthermore, the U.S.…
PEEP Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors
September 8, 2026 A newly disclosed post-exploitation toolkit called PEEP is turning Google Chrome and Microsoft Edge into persistent backdoors for host-level command execution. Cybersecurity researchers at SOCRadar disclosed the framework this week,…
IDScan Data Breach Exposes Driver’s Licenses in Dark-Web
September 6, 2026 Identity verification company IDScan is facing multiple lawsuits after hackers allegedly breached its systems and offered more than 153 million U.S. and Canadian driver’s licenses for sale on a dark-web identity theft service…
Critical Citrix NetScaler Authentication Bypass CVE Under Active Exploitation
September 5, 2026 Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway, following the public release of proof-of-concept exploit code on September 4, 2026. The flaw, tracked as…
Critical JFrog Artifactory Auth Bypass CVE Under Active Exploitation
September 1, 2026 JFrog has released an emergency patch for a critical authentication bypass vulnerability in Artifactory, tracked as CVE-2026-82329 (CVSS 9.8), that allows unauthenticated remote attackers to obtain full administrative access. Security…
ShinyHunters Steals 284 Million Healthcare Records in Vishing Attack
August 30, 2026 Healthcare and pharmaceutical distribution giant McKesson has disclosed a significant cybersecurity incident. The company confirmed unauthorized access to third-party applications and data exfiltration. Consequently, the ShinyHunters…
Check Point Researchers Weaponize Microsoft Defender Remediation Driver for Kernel-Level Attacks
August 23, 2026 Check Point Research has disclosed a technique that weaponizes Microsoft Defender’s own signed boot-time remediation driver, BTR.sys, to execute arbitrary kernel-level file and registry operations on fully patched Windows systems.…