CVE-2026-19490: Citrix NetScaler Authentication Bypass Moves From PoC to Real-World Exploitation Attempts
The targeting of CVE-2026-19490 against Citrix NetScaler ADC and NetScaler Gateway appliances is particularly concerning because the vulnerable systems often sit directly on the enterprise perimeter a…
Sep 04, 2026
IDScan.net Breach Allegations Expose the Hidden Risk of Centralized Identity Verification
Reports linking IDScan.net to a dark-web marketplace offering access to more than 153 million U.S. and Canadian driver’s-license records highlight one of the most uncomfortable contradictions in…
Sep 04, 2026
CVE-2026-75925: Critical IXON VPN Client Flaw Enables Root or SYSTEM Command Execution
CISA’s ICSA-26-246-02 advisory covers a critical vulnerability in the IXON VPN Client that could allow an attacker to execute commands with root or SYSTEM privileges on the computer running the …
Sep 04, 2026
Attackers Turn Trusted Node.js Into a Malware Runtime, Showing Why Signed Software Alone Cannot Be Trusted
The growing abuse of Node.js in targeted attacks is another example of how threat actors increasingly prefer to operate through trusted software rather than introduce obviously malicious binaries. Acc…
Sep 04, 2026
CVE-2026-78012: Critical NetStaX EtherNet/IP Flaw Exposes Industrial Devices to Memory Corruption and Remote Attack
CISA’s ICSA-26-246-07 advisory highlights a critical vulnerability in Pyramid Solutions’ NetStaX EtherNet/IP Stack that deserves particular attention because the weakness exists in a reusa…
Sep 04, 2026
Thomson Reuters C-Track Breach Exposes the Hidden Risk in Centralized Court Technology
The disclosure that an unauthorized party obtained files from Thomson Reuters’ C-Track court case-management environment highlights the unusually sensitive risks created when judicial systems de…
Sep 04, 2026
BraZetsu Turns Compromised Windows Systems Into Inventory for the Cybercrime Access Economy
The discovery of BraZetsu, a Python-based Windows malware framework linked by Group-IB to an operation tracked as Exilware, highlights an important evolution in the initial-access-broker economy. Inst…
Sep 04, 2026
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has disclosed a critical vulnerability in certain Silicon One-based Nexus 9000 Series switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.…
Sep 04, 2026
Coder Registry Compromise Turns Trusted Terraform Modules Into Credential-Stealing Supply-Chain Payloads
The compromise of Coder’s registry infrastructure is a strong reminder that software supply-chain attacks do not always require compromising source-code repositories or poisoning a package at th…
Sep 04, 2026
French Hospital Fined €500,000 After One Compromised Account Exposed Data of Over 727,000 People
The €500,000 fine imposed by France's data protection authority, CNIL, on Hôpital privé de la Loire provides an important reminder that a data breach is not automatically what …
Sep 04, 2026
Plex Urges Immediate Security Updates as Details of Multiple Vulnerabilities Remain Undisclosed.
Plex has urged users to update both Plex Media Server and Plex Desktop immediately after releasing fixes for multiple security vulnerabilities. The affected server versions include Plex Media Server 1…
Sep 03, 2026
FalconFlank PoC Turns CrowdStrike Remediation Into a Potential Privilege-Escalation Path
The public release of FalconFlank, a proof-of-concept claiming to demonstrate local privilege escalation through CrowdStrike Falcon Sensor, raises an important issue for endpoint security architecture…
Sep 03, 2026