Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Microsoft Internet Key Exchange (IKE) Service Extensions.
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Broadcom VMware vCenter.
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.1 (Critical). Affects Microsoft SharePoint.
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Apple macOS.
The Russian influence network CopyCop is conducting a targeted campaign against Western-backed AI and infrastructure initiatives in Armenia, specifically focusing on the Firebird AI data center. The operation appears designed to obstruct Armenia's shift toward Western alignment by undermining key technology projects in the region.
North Korean threat actor PurpleDelta conducts fraudulent employment operations by leveraging AI-generated personas and custom ChatGPT assistants to infiltrate target organizations with sophisticated social engineering tradecraft. Security professionals can identify and defend against these campaigns by recognizing specific indicators of compromise and implementing targeted mitigation strategies outlined in Recorded Future's analysis.
Researchers have discovered an exploit chain combining two separate vulnerabilities in Unisoc modems that allows attackers to compromise Android devices through a simple phone call. The attack requires only that a victim answer the incoming call, after which an attacker can deliver a malicious payload to gain device control.
A critical GraphQL vulnerability in GitLab Community and Enterprise editions (CVE-2026-19478, CVSS 9.4) could allow unauthenticated attackers to remotely delete or modify public projects and user data under certain conditions. GitLab has released security updates to address the flaw, which represents a significant risk to instances exposed to untrusted networks.
VulnerabilitySANS Internet Storm Center·6 days ago
Apple released updates for iOS/iPadOS and macOS addressing 108 vulnerabilities across the platforms, arriving roughly two weeks after a targeted macOS patch for a screen-sharing flaw. The screen-sharing vulnerability patched in the previous update did not impact iOS/iPadOS devices.
Three testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, according to Anthropic.
A breach at Hugging Face has prompted security experts to scrutinize AI platform security practices, with Adam Shostack expressing surprise at details revealed by OpenAI regarding the incident. The attack highlights potential gaps in security controls that protect machine learning platforms and raises broader concerns about how AI companies safeguard sensitive data and systems.
Wiz researchers discovered a GitHub Actions workflow injection vulnerability in Snowflake's snowflake-connector-net repository that could allow attackers to execute arbitrary commands through a crafted GitHub issue, potentially exposing internal Jira credentials stored in the affected workflow. The flaw existed in the jira_issue.yml workflow file, which was triggered by GitHub issues, creating an attack vector for credential theft and unauthorized command execution.
A critical vulnerability in the widely-deployed Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files and achieve remote code execution on affected sites. Tracked as CVE-2026-15748 with a CVSS score of 9.8, the flaw poses a severe risk to the plugin's 600,000+ active installations. The vulnerability was discovered by a security researcher and demands immediate patching to prevent exploitation.
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the
A vulnerability in UNISOC modems allows attackers to achieve kernel-level code execution by exploiting video call functionality. This remote code execution capability represents a significant risk to devices using UNISOC chipsets, as the attack vector operates at a fundamental system level.
Linux botnet Evooo1Bot extends beyond traditional Mirai-style distributed denial-of-service attacks by incorporating exploitation modules, credential theft capabilities, and reverse SOCKS relays. These additions transform infected devices into versatile persistent infrastructure that attackers can leverage for multiple objectives beyond volumetric attacks. The expanded toolkit represents an evolution in botnet functionality that significantly increases the threat profile of compromised systems.
A critical vulnerability with a maximum severity score of 10 has been discovered in SAP Commerce Cloud, with initial exploitation attempts already underway. The flaw's perfect severity rating combined with apparent ease of exploitation presents an immediate risk to organizations running this platform.
Cybercrime group Storm-0501 has evolved beyond traditional endpoint ransomware to target Azure cloud environments directly, systematically disabling security controls like resource locks and backups to hijack entire cloud tenants. Tenable One Cloud Exposure uses AI-powered threat detection to map Storm-0501's tactics across the attack chain and correlate fragmented Azure activity logs into actionable threat stories for rapid containment. The shift to cloud-native ransomware demands cloud detection and response capabilities that can trace lateral movement, identify initial breach points, and guide immediate defensive actions like credential revocation and policy restoration.
A cybersecurity researcher has demonstrated how machine learning-generated patterns can effectively evade detection by Flock surveillance cameras, the AI-powered licence plate readers increasingly deployed across American streets. The technique uses computer-generated adversarial patterns to render vehicles invisible to these automated detection systems, raising significant concerns about the security and reliability of widespread surveillance infrastructure. This research highlights a potential vulnerability in licence plate reader technology that could have implications for law enforcement and public safety applications.
Wiz Red Agent autonomously identified and exploited a GitHub Actions injection vulnerability that bypassed GitHub's Advanced Security controls, gaining access to Snowflake's internal Jira and sensitive data within five days of the flaw going live. The vulnerability originated in a pull request assisted by GitHub Copilot, highlighting gaps in automated security detection. The red team agent independently assessed the breach's potential impact without requiring human direction.