Network Security

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension 2026-09-09 at 17:33 By Ionut Arghire The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension Read More »

Ivanti Patches Critical Flaws Across Enterprise Security Products

Ivanti Patches Critical Flaws Across Enterprise Security Products 2026-09-09 at 13:28 By Ionut Arghire Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek. This article is an excerpt […]

Ivanti Patches Critical Flaws Across Enterprise Security Products Read More »

MikroTik Patches Critical Flaws Chained to Hack Routers

MikroTik Patches Critical Flaws Chained to Hack Routers 2026-09-08 at 14:15 By Ionut Arghire Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

MikroTik Patches Critical Flaws Chained to Hack Routers Read More »

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation 2026-09-04 at 19:18 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud Patches, […]

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation Read More »

HPE Patches Critical RCE Vulnerabilities in AOS-CX

HPE Patches Critical RCE Vulnerabilities in AOS-CX 2026-09-04 at 19:11 By Ionut Arghire Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

HPE Patches Critical RCE Vulnerabilities in AOS-CX Read More »

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities 2026-09-03 at 13:30 By Ionut Arghire Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass. The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared […]

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities Read More »

Malicious Virtualizor Update Served via BGP Hijacking

Malicious Virtualizor Update Served via BGP Hijacking 2026-09-02 at 14:31 By Ionut Arghire Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. The post Malicious Virtualizor Update Served via BGP Hijacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Malicious Virtualizor Update Served via BGP Hijacking Read More »

Deployed Is Not Defended: The Quiet Gaps Hiding in Your Zscaler Environment

Deployed Is Not Defended: The Quiet Gaps Hiding in Your Zscaler Environment 2026-08-04 at 17:00 By Jason Sargent You deployedZscaler, passed the audit, and got leadership’s sign-off. The project closed, and the dashboard has been green ever since. That moment is usually right about when the real risk starts to take shape. This article is […]

Deployed Is Not Defended: The Quiet Gaps Hiding in Your Zscaler Environment Read More »

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover 2026-08-04 at 15:00 By Eduard Kovacs Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem. The post TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Read More »

‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale

‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale 2026-07-30 at 15:15 By Kevin Townsend Researchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains. The post ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale appeared first on SecurityWeek. This […]

‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale Read More »

Palo Alto Networks to Acquire Observability Platform Provider Embrace

Palo Alto Networks to Acquire Observability Platform Provider Embrace 2026-07-22 at 17:58 By SecurityWeek News Acquisition follows January’s Chronosphere deal, deepening Palo Alto Networks’ push beyond core security into observability. The post Palo Alto Networks to Acquire Observability Platform Provider Embrace appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Palo Alto Networks to Acquire Observability Platform Provider Embrace Read More »

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors 2026-07-08 at 18:42 By Ionut Arghire Cisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors. The post China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors appeared first on SecurityWeek. This article is an excerpt […]

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors Read More »

FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks

FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks 2026-07-02 at 15:34 By Ionut Arghire Researchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations. The post FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks appeared first on SecurityWeek. This article is […]

FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks Read More »

Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack

Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack 2026-07-01 at 14:20 By Ionut Arghire Citrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug. The post Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack appeared first on SecurityWeek. This article is […]

Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack Read More »

Hackers Exploiting Cisco Unified CM Vulnerability

Hackers Exploiting Cisco Unified CM Vulnerability 2026-06-24 at 08:44 By Eduard Kovacs Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June. The post Hackers Exploiting Cisco Unified CM Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Exploiting Cisco Unified CM Vulnerability Read More »

FortiBleed: 86,000 Fortinet Device Credentials Compromised

FortiBleed: 86,000 Fortinet Device Credentials Compromised 2026-06-19 at 13:48 By Ionut Arghire The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs. The post FortiBleed: 86,000 Fortinet Device Credentials Compromised appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

FortiBleed: 86,000 Fortinet Device Credentials Compromised Read More »

Critical Command Execution Vulnerability Patched in Cisco ISE

Critical Command Execution Vulnerability Patched in Cisco ISE 2026-06-18 at 13:27 By Ionut Arghire Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root. The post Critical Command Execution Vulnerability Patched in Cisco ISE appeared first on SecurityWeek. This article is an excerpt from […]

Critical Command Execution Vulnerability Patched in Cisco ISE Read More »

Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks

Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks 2026-06-16 at 09:20 By Eduard Kovacs Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write. The post Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks Read More »

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks 2026-05-28 at 15:55 By Ionut Arghire Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching. The post Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks appeared first on SecurityWeek. This […]

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks Read More »

Scroll to Top