Fortinet patches actively exploited FortiOS SSO auth bypass (CVE-2026-24858)

5 days ago

Fortinet released fixes for a critical FortiOS SSO auth bypass (CVE-2026-24858) actively exploited, impacting FortiOS, FortiManager, and FortiAnalyzer. Fortinet started…

PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and Bun

5 days ago

Koi researchers found “PackageGate” flaws in NPM, PNPM, VLT, and Bun that let attackers perform supply chain attacks and run…

WhatsApp rolls out Strict Account settings to strengthen protection for high-risk users

5 days ago

Meta announced new Strict Account Settings on WhatsApp to better protect high-risk users from advanced cyber attacks. Meta announced new…

Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online

6 days ago

Shadowserver researchers found 6,000+ SmarterMail servers exposed online and likely vulnerable to a critical auth bypass flaw. Nonprofit security organization…

U.S. CISA adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

6 days ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known…

Amnesia RAT deployed in multi-stage phishing attacks against Russian users

6 days ago

A multi-stage phishing campaign targets users in Russia with ransomware and Amnesia RAT using fake business documents as lures. FortiGuard…

Dormakaba flaws allow to access major organizations’ doors

6 days ago

Researchers found over 20 flaws in Dormakaba access systems that could let attackers remotely unlock doors at major organizations. Researchers…

Emergency Microsoft update fixes in-the-wild Office zero-day

6 days ago

Microsoft issued emergency updates to fix an actively exploited Office zero-day, CVE-2026-21509, affecting Office 2016–2024 and Microsoft 365 Apps. Microsoft…

ShinyHunters claims 2 Million Crunchbase records; company confirms breach

7 days ago

Crunchbase confirms a data breach after cybercrime group ShinyHunters claims to have stolen over 2 million personal records. Crunchbase confirmed…

Energy sector targeted in multi-stage phishing and BEC campaign using SharePoint

7 days ago

Microsoft warns of a multi-stage phishing and BEC campaign hitting energy firms, abusing SharePoint links and inbox rules to steal…

This website uses cookies.