Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
A maximum-severity path traversal bug in Adobe ColdFusion, tracked as CVE-2026-48282, is under active exploitation and now sits in CISA's Known Exploited Vulnerabilities catalog.
Why it matters: If you run ColdFusion anywhere in your stack, patch or isolate it now and pull server access logs for the exploitation window — path traversal bugs like this are trivial to weaponize once public, and the KEV listing means opportunistic scanning has already started.
Read source →Accenture acknowledged a security incident after a threat actor posted claims of stealing 35GB of source code, RSA and SSH keys, and Azure access tokens from an internal DevOps repository.
Why it matters: This is a supply-chain exposure, not just an Accenture problem — if Accenture is a vendor or systems integrator in your environment, ask them directly whether any of your credentials, access keys, or integration code were stored in the affected repository.
Read source →A phishing-as-a-service platform dubbed DEBULL is using collaboration-themed lures and the legitimate Microsoft device-code login flow to take over Microsoft 365 accounts without ever touching a password.
Why it matters: Device-code phishing bypasses your password and MFA prompts entirely by tricking users into authorizing a real Microsoft session — if you haven't already, restrict or disable the device code auth flow in Entra ID via Conditional Access unless a specific business case requires it.
Read source →Attackers are exploiting CVE-2026-20896, a reverse-proxy trust misconfiguration in Gitea Docker images, to bypass authentication with one crafted HTTP header and reach private repositories and secrets.
Why it matters: If you self-host Gitea in Docker, check your REVERSE_PROXY_TRUSTED_PROXIES setting today — the default in vulnerable images trusts every source IP, which means anyone on the network can impersonate an admin with a single header.
Read source →Check Point Research uncovered Cavern, a previously undocumented .NET-based C2 framework used by an Iranian MOIS-linked group to breach Israeli IT providers and government targets.
Why it matters: This is a supply-chain campaign first and an Israel-specific campaign second — the group reaches its real targets by hopping through trusted IT providers. If you're an Israeli startup working with external MSPs or IT vendors, ask them directly what monitoring they have on outbound connections from their management tooling.
Read source →4,700 victims were listed on ransomware leak sites in H1 2026, up 16% year-over-year and nearly 65% versus the same period in 2024.
Why it matters: A steady year-over-year rise in leak-site postings means ransomware groups are successfully breaching and extorting more organizations, not fewer — this is the moment to confirm your detection coverage for lateral movement and data staging, not just initial access, since that's where most of these incidents are still caught too late.
Read source →Attackers planted malicious code on Polymarket via a third-party vendor, stealing roughly $3M from users. Polymarket has pledged to reimburse affected accounts.
Why it matters: Third-party JavaScript and vendor scripts running on customer-facing pages are a direct path to account and fund theft — review what third-party code executes in your own web properties and whether you'd detect it injecting or exfiltrating data.
Read source →OpenAI releases three new models under GPT-5.6, with flagship model Sol matching rival Mythos on benchmarks using a third of the output tokens.
Why it matters: Sol's stated focus on both offensive research assistance and model self-defense means attacker tooling and AI-assisted vulnerability discovery are about to get faster — factor that into your threat model and detection priorities, not just your engineering roadmap.
Read source →More organizations report data leaks from the Oracle PeopleSoft vulnerability, including Nissan factory workers and insurance regulator NAIC.
Why it matters: When a single vendor vulnerability produces a wave of unrelated victims over weeks, assume your own PeopleSoft instances are still exposed until you've confirmed patching and reviewed logs for the exploitation window, not just applied the fix.
Read source →Japanese auto parts manufacturer Nidec Corporation, with roughly $17B in annual revenue, falls victim to a ransomware attack claimed by the Blackfield group.
Why it matters: A $2M demand against a $17B-revenue manufacturer is a rounding error for the attacker to price low and for the victim to consider paying — ransomware groups increasingly calibrate demands to maximize the odds of a quick payout rather than to match victim size, which should factor into your own incident response cost-benefit planning.
Read source →