← Home

Global Cyber Intelligence

Worldwide Cyber Security News

Curated cyber security intelligence from national cyber agencies, independent researchers, and leading industry media across North America, Europe, the United Kingdom, and the Asia-Pacific region. Updated every thirty minutes.

14authoritative sources
11live right now
245stories indexed

Showing 29 of 29 matching stories

Last refreshed 14:49 UTC

  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Ivanti Patches Critical Flaws Across Enterprise Security Products

    Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek .

    SecurityWeek · 4h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Chrome 153 Patches Seventh Zero-Day of 2026

    The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek .

    SecurityWeek · 5h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

    Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

    The Hacker News · 5h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

    The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

    The Hacker News · 8h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP

    The Hacker News · 8h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

    Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.

    The Hacker News · 10h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

    The Hacker News · 10h agoRead at source →
  • Vulnerability & ExploitCriticalNorth AmericaIndustry Media

    Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

    While the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure. The post Microsoft discloses two actively exploited zero-days among 974 vulnerabilities appeared first on CyberScoop .

    CyberScoop · 16h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndependent Research

    September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

    This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.

    SANS Internet Storm Center · 19h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek .

    SecurityWeek · 20h agoRead at source →
  • Vulnerability & ExploitCriticalNorth AmericaGovernment CERT

    CISA Adds Four Known Exploited Vulnerabilities to Catalog

    CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability   CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability  CVE-2026-86218 N-able N-central Static Code Injection Vulnerability  These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities . CISA will continue to add vulnerabilities to the catalog that meet the specified criteria . Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. 

    CISA — Cybersecurity and Infrastructure Security Agency · 1d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

    Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

    The Hacker News · 1d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

    The Hacker News · 2d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

    The Hacker News · 2d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

    The Hacker News · 3d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

    JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

    The Hacker News · 3d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

    Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

    The Hacker News · 3d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

    Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

    The Hacker News · 4d agoRead at source →
  • Vulnerability & ExploitCriticalNorth AmericaGovernment CERT

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities . CISA will continue to add vulnerabilities to the catalog that meet the specified criteria . Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. 

    CISA — Cybersecurity and Infrastructure Security Agency · 5d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

    Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

    The Hacker News · 5d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

    Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote

    The Hacker News · 5d agoRead at source →
  • Vulnerability & ExploitCriticalNorth AmericaIndustry Media

    Attackers exploit zero-days in consistently besieged SonicWall product

    SonicWall customers have confronted a barrage of attacks for years, including five actively exploited vulnerabilities in SMA 1000 appliances since late 2025. The post Attackers exploit zero-days in consistently besieged SonicWall product appeared first on CyberScoop .

    CyberScoop · 5d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

    The Hacker News · 5d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

    The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

    Dark Reading · 6d ago
  • Vulnerability & ExploitCriticalNorth AmericaGovernment CERT

    CISA Adds Seven Known Exploited Vulnerabilities to Catalog

    CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability  CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability  CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability  CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability  CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability  CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability  CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability  These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.  Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.  While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities . CISA will continue to add vulnerabilities to the catalog that meet the specified criteria .  Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomina

    CISA — Cybersecurity and Infrastructure Security Agency · 2026-09-02Read at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Attackers Pounce on Critical Artifactory Bug Following Disclosure

    CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.

    Dark Reading · 2026-09-01
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

    The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.

    Dark Reading · 2026-09-01
  • Vulnerability & ExploitCriticalNorth AmericaGovernment CERT

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability  CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability  These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.  Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.  While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities . CISA will continue to add vulnerabilities to the catalog that meet the specified criteria .  Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. 

    CISA — Cybersecurity and Infrastructure Security Agency · 2026-08-31Read at source →
  • Vulnerability & ExploitCriticalGlobalIndependent Research

    Microsoft Plugs Nearly 400 Security Holes

    Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

    Krebs on Security · 2026-08-11Read at source →

Indexed sources

Every item displayed here links back to the original publication. CyberZonic does not host or re-publish full article text.