Security News

Curated cybersecurity news and emerging threats relevant to startups, SMBs, and growing teams.

Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.

Each item includes our perspective on why it matters to your security posture.

Microsoft Patches 'RoguePlanet' Defender Flaw That Grants SYSTEM Privileges

Vulnerability AWS Tools

CVE-2026-50656, a race condition in the Microsoft Malware Protection Engine, let local attackers spawn a SYSTEM-level shell on fully patched Windows hosts. Microsoft has shipped a fix.

Why it matters: The irony here is the attack surface: your endpoint protection engine itself. Confirm the Malware Protection Engine has auto-updated to 1.1.26060.3008 or later across your fleet — this doesn't wait for a normal patch cycle, but it's worth verifying rather than assuming.
Read source →

GodDamn Ransomware Uses Signed PoisonX Driver to Blind Endpoint Defenses

Incident Response Vulnerability Threat Intelligence

A ransomware family tied to the Hyadina group (rebranded from Beast) uses a Microsoft-signed malicious kernel driver, AnyDesk, and PsExec to disable security tooling before encrypting data.

Why it matters: A signed kernel driver bypassing your EDR is a detection-layer problem, not a patching problem. Make sure your monitoring flags unexpected kernel driver loads and known dual-use remote access tools like AnyDesk and PsExec running outside of change-managed maintenance windows.
Read source →

Ubiquiti Patches Maximum-Severity UniFi OS Command Injection Flaw

Vulnerability Tools

Ubiquiti shipped fixes for seven critical UniFi OS vulnerabilities, including CVE-2026-50746, an unauthenticated CVSS 10.0 command injection bug reachable by any device on the same network segment.

Why it matters: Confirm your UniFi Connect, Access, Protect, Talk, and OS deployments are on the patched builds — CVE-2026-50746 needs no authentication and no more than network adjacency, which describes most guest or IoT VLANs that share a segment with management infrastructure.
Read source →

JadePuffer: First Documented Ransomware Attack Run End-to-End by an AI Agent

Threat Intelligence Incident Response Vulnerability

Sysdig researchers found JadePuffer, a ransomware operation where an autonomous LLM agent handled recon, credential theft, lateral movement, and encryption without a human operator.

Why it matters: The individual steps here aren't new — the automation is. If your detection rules assume a human operator's pacing and mistakes, this incident is a signal to test them against faster, self-correcting behavior, and to prioritize patching internet-facing AI tooling like Langflow before attackers' agents get there first.
Read source →

CISA Orders Agencies to Patch Actively Exploited Adobe ColdFusion Flaw

Vulnerability Incident Response

A maximum-severity path traversal bug in Adobe ColdFusion, tracked as CVE-2026-48282, is under active exploitation and now sits in CISA's Known Exploited Vulnerabilities catalog.

Why it matters: If you run ColdFusion anywhere in your stack, patch or isolate it now and pull server access logs for the exploitation window — path traversal bugs like this are trivial to weaponize once public, and the KEV listing means opportunistic scanning has already started.
Read source →

Accenture Confirms Breach After Hacker Claims Theft of 35GB Source Code

Incident Response Supply Chain

Accenture acknowledged a security incident after a threat actor posted claims of stealing 35GB of source code, RSA and SSH keys, and Azure access tokens from an internal DevOps repository.

Why it matters: This is a supply-chain exposure, not just an Accenture problem — if Accenture is a vendor or systems integrator in your environment, ask them directly whether any of your credentials, access keys, or integration code were stored in the affected repository.
Read source →

DEBULL Phishing-as-a-Service Abuses Microsoft Device Code Flow to Hijack M365 Accounts

Threat Intelligence Identity & Access

A phishing-as-a-service platform dubbed DEBULL is using collaboration-themed lures and the legitimate Microsoft device-code login flow to take over Microsoft 365 accounts without ever touching a password.

Why it matters: Device-code phishing bypasses your password and MFA prompts entirely by tricking users into authorizing a real Microsoft session — if you haven't already, restrict or disable the device code auth flow in Entra ID via Conditional Access unless a specific business case requires it.
Read source →

Critical Gitea Docker Auth Bypass Under Active Exploitation via Single HTTP Header

Vulnerability Tools

Attackers are exploiting CVE-2026-20896, a reverse-proxy trust misconfiguration in Gitea Docker images, to bypass authentication with one crafted HTTP header and reach private repositories and secrets.

Why it matters: If you self-host Gitea in Docker, check your REVERSE_PROXY_TRUSTED_PROXIES setting today — the default in vulnerable images trusts every source IP, which means anyone on the network can impersonate an admin with a single header.
Read source →

Iran-Linked 'Cavern Manticore' Deploys New Modular C2 Framework Against Israeli Orgs

Threat Intelligence Incident Response Identity & Access

Check Point Research uncovered Cavern, a previously undocumented .NET-based C2 framework used by an Iranian MOIS-linked group to breach Israeli IT providers and government targets.

Why it matters: This is a supply-chain campaign first and an Israel-specific campaign second — the group reaches its real targets by hopping through trusted IT providers. If you're an Israeli startup working with external MSPs or IT vendors, ask them directly what monitoring they have on outbound connections from their management tooling.
Read source →

Ransomware Victim Postings Hit Record High in First Half of 2026

Incident Response Threat Intelligence

4,700 victims were listed on ransomware leak sites in H1 2026, up 16% year-over-year and nearly 65% versus the same period in 2024.

Why it matters: A steady year-over-year rise in leak-site postings means ransomware groups are successfully breaching and extorting more organizations, not fewer — this is the moment to confirm your detection coverage for lateral movement and data staging, not just initial access, since that's where most of these incidents are still caught too late.
Read source →