-
Cisco has released important security updates for Catalyst SD-WAN Software after discovering several critical vulnerabilities that could allow for access control bypass, unauthorized privilege escalation, and exposure of sensitive data. The most severe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A long‑running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command‑and‑control (C2) traffic never tou…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Stolen Greatness authentication tokens are providing sustained, MFA‑approved access to victim Microsoft 365 tenants for more than two weeks after the initial phish, underscoring that token replay – not password theft – is driving the persistence in thi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft’s Bug Bounty Program awarded over $20 million to 562 security researchers this year, marking the highest total payout and the largest number of recognized researchers in the program’s history. Contributors hailed from 64 countries…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel’s Open vSwitch (OVS) implementation. This vulnerability could allow unprivileged local users to gain roo…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack devices, compromise controllers, expose credentials, and create access points into internal networ…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake Open VSX extensions have hijacked high‑trust namespaces like AMD, Azure, Salesforce, Hyperledger, and a U.S. government agency on the Open VSX Registry, silently harvesting Git and CI metadata from developer and CI environments while posing as leg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ScreenConnect is being systematically weaponized in the SMOKE#SCREEN campaign, where attackers hide execution windows, delete installers, and disguise malicious activity as routine software updates to plant fully functional, signed ScreenConnect agents…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Veeam has issued security updates to address multiple vulnerabilities in Veeam ONE, including a critical flaw that could enable an unauthenticated remote attacker to execute arbitrary code on an affected agent host. This issue, identified as CVE-2026-6…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware operators are now abusing Ethereum smart contracts as stealthy command‑and‑control resolvers, with a Gentlemen ransomware affiliate using the EtherRAT backdoor to pull rotating C2 domains directly from the blockchain instead of hardcoding th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


