Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
A Cisco ASA/FTD firewall DoS flaw hits its federal patch deadline today, an unpatched GeoServer SQL injection zero-day is under active attack, Adobe Commerce's account-takeover bug was targeted within hours of disclosure, and Trezor becomes the latest named victim of this month's Metabase breach wave.
Read source →Lazarus Group used fake defense-sector job offers to run a Windows kernel zero-day for five weeks before Patch Tuesday closed it, a VMware vCenter flaw is under exploitation in 47 countries, a Defender zero-day ships with no fix, and Sandworm trojans WireGuard to hit sysadmins.
Read source →Microsoft's August Patch Tuesday closes a WinSock zero-day already exploited for SYSTEM privilege escalation, Black Hat researchers disclose NatJack — a whole class of NAT flaws that hijacks TCP sessions and spoofs DNS — nearly 800 npm packages ship a RAT without touching install hooks, and Cisco discloses ClamAV parser flaws with public exploit code.
Read source →A private cellular network becomes a new path into OT networks after a second Polish energy facility is sabotaged, an unpatched Red Hat ACM flaw hands cluster-admin to any namespace editor, CISA details how Gunra ransomware turns exposed VPNs into full network compromise, and DeadLock ransomware blinds Windows logging before it encrypts.
Read source →A CVSS 10 Metabase SQL injection zero-day breaches customer BI instances, two federal KEV patch deadlines land the same day, Kimsuky builds local LLM tooling for its operators, and Levi Strauss discloses a vishing breach.
Read source →TeamCity's unauthenticated RCE is now exploited past its federal KEV deadline, a one-click Atlassian Rovo AI flaw could leak Jira data, and DPRK npm packages hide C2 in Ethereum transfers.
Read source →WordPress ships an emergency patch for a pre-auth XSS chain that escalates to PHP code execution; CrowdStrike's new threat report finds device-code phishing up 15-fold in 2026; and a Bank of America phishing campaign quietly installs remote-access malware that resists uninstalling.
Read source →A 13-year-old Linux kernel bug called OVSwrap hands root to any local user on nearly every major distro; 15 chained TP-Link Omada flaws let attackers hijack routers and camera feeds from Black Hat; and Google's own malware-detection automation mass-locks hundreds of legitimate Blogger sites.
Read source →A hijacked maintainer account turns the keyv npm family into a credential-stealing worm that plants Claude Code hooks; a reseller called Poison Claude proxies AI prompts through infrastructure it controls; and Clop ransomware extorts a new victim with hex-named JSP web shells on PTC Windchill.
Read source →CISA adds a critical, unauthenticated Langflow RCE with a public Metasploit module to its KEV catalog; a trojanized QuickFox VPN installer delivers the Mustang Panda-linked FDMTP backdoor to Chinese diaspora users; and a critical cPanel & WHM flaw lets any hosting customer run SQL as database root.
Read source →