vulnerability

AI agents exploited PaperCut flaws to breach 395 organizations

AI agents exploited PaperCut flaws to breach 395 organizations 2026-09-11 at 13:05 By Sinisa Markovic A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise. The result was […]

AI agents exploited PaperCut flaws to breach 395 organizations Read More »

Critical NetScaler Vulnerability Exploited in Attacks

Critical NetScaler Vulnerability Exploited in Attacks 2026-09-10 at 15:20 By Ionut Arghire Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The post Critical NetScaler Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical NetScaler Vulnerability Exploited in Attacks Read More »

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) 2026-09-10 at 14:22 By Zeljka Zorz State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabilities under […]

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) Read More »

Organizations Warned of Cisco Secure FMC Exploitation

Organizations Warned of Cisco Secure FMC Exploitation 2026-09-10 at 13:06 By Eduard Kovacs Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Organizations Warned of Cisco Secure FMC Exploitation Read More »

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks 2026-09-10 at 09:33 By Ionut Arghire The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026. The post Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Read More »

Android’s September 2026 Updates Patch 180 Vulnerabilities

Android’s September 2026 Updates Patch 180 Vulnerabilities 2026-09-09 at 19:30 By Ionut Arghire The security updates resolve critical flaws across Android’s Framework, System, and Kernel components. The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Android’s September 2026 Updates Patch 180 Vulnerabilities Read More »

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) 2026-09-09 at 10:53 By Sinisa Markovic Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has been […]

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) Read More »

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication 2026-09-07 at 17:07 By Sinisa Markovic Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland’s national CSIRT team, have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTik. […]

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication Read More »

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores 2026-09-07 at 14:58 By Ionut Arghire The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Read More »

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) 2026-09-07 at 14:55 By Sinisa Markovic N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability […]

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) Read More »

Attackers spread malware through ScreenConnect file transfers

Attackers spread malware through ScreenConnect file transfers 2026-09-07 at 12:13 By Sinisa Markovic A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. “A CVE identifier and an official fix will be issued within the week,” the company wrote in its September 3 advisory. ScreenConnect […]

Attackers spread malware through ScreenConnect file transfers Read More »

Google patches actively exploited Chrome zero-day (CVE-2026-85046)

Google patches actively exploited Chrome zero-day (CVE-2026-85046) 2026-09-04 at 15:09 By Sinisa Markovic Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thursday security advisory. The fix […]

Google patches actively exploited Chrome zero-day (CVE-2026-85046) Read More »

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability 2026-09-03 at 13:40 By Ionut Arghire The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability Read More »

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) 2026-09-02 at 16:24 By Sinisa Markovic Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026-62911 […]

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) Read More »

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) 2026-09-02 at 15:42 By Zeljka Zorz A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unified communications platform built on […]

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) Read More »

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products 2026-09-02 at 15:39 By Eduard Kovacs The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products. The post Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products Read More »

Exploit Published for Fresh Cleo Harmony Vulnerability

Exploit Published for Fresh Cleo Harmony Vulnerability 2026-09-02 at 15:18 By Ionut Arghire The security defect allows remote attackers to bypass authentication through argument bearer manipulation. The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploit Published for Fresh Cleo Harmony Vulnerability Read More »

Chrome and Firefox Updates Patch Dozens of Vulnerabilities

Chrome and Firefox Updates Patch Dozens of Vulnerabilities 2026-09-02 at 12:12 By Ionut Arghire The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs. The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome and Firefox Updates Patch Dozens of Vulnerabilities Read More »

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks 2026-09-02 at 08:04 By Eduard Kovacs The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks Read More »

Scroll to Top