CrowdStrike FalconFlank Zero-Day EDR Platform Exploited
September 4, 2026 An anonymous security researcher operating under the handle “Nightmare Eclipse” has released a zero-day privilege escalation exploit targeting CrowdStrike Falcon, the widely deployed endpoint detection and response (EDR)…
Google Chrome V8 Zero-Day CVE Actively Exploited
September 3, 2026 Google released an emergency security update for Chrome on September 3, 2026, to patch an actively exploited zero-day vulnerability in the V8 JavaScript engine. The high-severity flaw, tracked as CVE-2026-85046, allows remote attackers…
Sangoma Switchvox SQL Injection Under Active Exploitation
Threat actors are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, an enterprise VoIP management platform. The flaw allows remote code execution without any credentials, and researchers have observed…
SonicWall SMA1000 Zero-Day Flaws Under Active Exploitation
Threat actors are actively chaining two critical zero-day vulnerabilities in SonicWall SMA1000 remote access appliances to achieve remote code execution on enterprise devices. The vulnerabilities, tracked as CVE-2026-83548 and CVE-2026-83549, affect…
Fire Ant Espionage Campaign Hijacks Cisco Routers
August 31, 2026 A China-nexus cyber espionage actor tracked as Fire Ant has evolved beyond hypervisor compromise to hijack Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Consequently, the group turns trusted network…
Socket Uncovers 19 Malicious Chrome and Edge Extensions Stealing Crypto Wallets and Credentials
August 30, 2026 Socket researchers have uncovered a sprawling malware campaign hidden inside 19 browser extensions for Google Chrome and Microsoft Edge. Furthermore, the malicious framework steals cryptocurrency wallet secrets, harvests credentials, and…
PaperCut Releases Second Emergency Patch After Attackers Bypass Initial Fixes
August 29, 2026 PaperCut has released a second emergency security patch for two critical vulnerabilities in its PaperCut NG and PaperCut MF print management software after security researchers discovered multiple methods to bypass the original emergency…
CISA Imposes 3-Day Patch Mandate on Perfect-10 Oracle WebLogic Proxy Flaw
August 28, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has imposed its tightest emergency patch mandate on a maximum-severity Oracle vulnerability that China-linked threat actors have exploited across government and commercial…
Unpatched Calix GS7 XGS Router CVE Lets Attackers Bypass NAT and Expose Internal Devices
August 24, 2026 An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to bypass NAT and firewall protections and expose internal network devices to the public internet. The flaw, tracked as CVE-2026-75501, affects…
Critical Elementor Pro CVE Enables Unauthenticated RCE on WordPress Sites
August 23, 2026 A critical vulnerability in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload executable PHP files for remote code execution on affected servers. Furthermore, the flaw has been actively disclosed and patched,…