← Home

Global Cyber Intelligence

Worldwide Cyber Security News

Curated cyber security intelligence from national cyber agencies, independent researchers, and leading industry media across North America, Europe, the United Kingdom, and the Asia-Pacific region. Updated every thirty minutes.

14authoritative sources
11live right now
245stories indexed

Showing 25 of 25 matching stories

Last refreshed 14:48 UTC

  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Ivanti Patches Critical Flaws Across Enterprise Security Products

    Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek .

    SecurityWeek · 4h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Chrome 153 Patches Seventh Zero-Day of 2026

    The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek .

    SecurityWeek · 5h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

    Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

    The Hacker News · 5h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

    The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

    The Hacker News · 8h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP

    The Hacker News · 8h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

    Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.

    The Hacker News · 10h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

    The Hacker News · 10h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndependent Research

    September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

    This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.

    SANS Internet Storm Center · 19h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek .

    SecurityWeek · 20h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

    Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

    The Hacker News · 1d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

    The Hacker News · 2d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

    The Hacker News · 2d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

    The Hacker News · 3d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

    JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

    The Hacker News · 3d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

    Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

    The Hacker News · 3d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

    Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

    The Hacker News · 4d agoRead at source →
  • Vulnerability & ExploitInformationalGlobalIndustry Media

    PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

    PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are

    The Hacker News · 4d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

    Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

    The Hacker News · 5d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

    Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote

    The Hacker News · 5d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

    The Hacker News · 5d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

    The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

    Dark Reading · 6d ago
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Attackers Pounce on Critical Artifactory Bug Following Disclosure

    CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.

    Dark Reading · 2026-09-01
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

    The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.

    Dark Reading · 2026-09-01
  • Vulnerability & ExploitInformationalGlobalIndustry Media

    Exploited Zimbra Flaw Highlights Shrinking Window to Patch

    CISA issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.

    Dark Reading · 2026-08-24
  • Vulnerability & ExploitCriticalGlobalIndependent Research

    Microsoft Plugs Nearly 400 Security Holes

    Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

    Krebs on Security · 2026-08-11Read at source →

Indexed sources

Every item displayed here links back to the original publication. CyberZonic does not host or re-publish full article text.