Stay informed about the latest cybersecurity threats, vulnerabilities, malware campaigns, phishing trends, supply-chain attacks, and security advisories. This section provides timely updates and practical insights to help organizations understand emerging risks and strengthen their security posture.
CISA’s advisory on Kieback & Peter DDC Building Controllers is another reminder that building automation systems are now part of the cyber-risk surface, not just facilities infrastructure. These controllers are used to regulate and monitor HVAC and building operations, and Kie…
The Hacker News article highlights an important shift in phishing: attackers are no longer always trying to steal passwords. They are increasingly trying to trick users into approving OAuth consent, which can give attackers long-lived access tokens to mailboxes, files, calenda…
The Drupal advisory is a clear reminder that CMS platforms remain high-value targets because they sit directly on the public internet and often power business-critical websites. Drupal has announced an urgent core security release for all supported branches on May 20, 2026, wa…
The SEPPMail Secure E-Mail Gateway vulnerabilities are a strong reminder that security gateways themselves must be treated as high-value attack surfaces. According to the report, multiple flaws could allow attackers to achieve remote code execution, read arbitrary mail, access…
The compromised Nx Console 18.95.0 incident is a serious reminder that developer tools have become a direct path into enterprise environments. According to the report, a malicious version of the Nx Console extension was published to the VS Code Marketplace and, once a develope…
The Trapdoor Android ad-fraud campaign shows how mobile threats are becoming more layered and harder to detect. Researchers found that the operation involved 455 malicious Android apps and 183 attacker-controlled C2 domains, generating up to 659 million bid requests per day. W…
The 7-Eleven data breach claimed by ShinyHunters is another reminder that large retail brands must secure not only customer-facing systems, but also franchisee, document-management, and SaaS environments. 7-Eleven confirmed that an unauthorized third party accessed certain sys…
CISA’s advisory on ZKTeco CCTV Cameras highlights why physical security devices must be managed with the same discipline as core IT infrastructure. The issue affects the SSC335-GC2063-Face-0b77 solution, where vulnerabilities may allow authentication bypass leading to full adm…
View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthentic…
The GitHub Actions supply-chain attack against actions-cool/issues-helper is a serious reminder that CI/CD pipelines are now prime targets for credential theft. In this case, attackers reportedly moved existing GitHub Action tags to point to an imposter commit containing malic…
The SHub “Reaper” macOS infostealer campaign shows how attackers are rapidly adapting to platform security improvements. Instead of relying only on older ClickFix-style Terminal tricks, this variant abuses the applescript:// URL scheme to open Script Editor with malicious Appl…
The reported exposure of AWS GovCloud keys and internal CISA credentials on a public GitHub repository is a stark reminder that secret management failures can undermine even the most security-focused organizations. According to the report, the repository exposed highly privile…
The analysis of Fast16 shows that cyber sabotage against industrial and scientific systems predates Stuxnet and has been far more specialized than many organizations assume. Unlike generic malware, Fast16 was reportedly designed to manipulate nuclear weapons simulation outputs…
The public exploit for DirtyDecrypt raises the urgency for Linux administrators because this is no longer just a theoretical kernel flaw. The vulnerability is a local privilege escalation issue in the Linux kernel’s rxgk module, and the available proof-of-concept can allow att…
The MiniPlasma Windows zero-day is a serious reminder that endpoint compromise does not end at initial access. Once an attacker gains a foothold on a Windows system, local privilege escalation flaws can turn limited access into full SYSTEM-level control, allowing deeper persis…
Tycoon2FA’s use of Microsoft 365 device-code phishing shows how attackers are adapting to bypass traditional MFA expectations without needing to steal passwords directly. By tricking users into entering an attacker-generated code on Microsoft’s legitimate device-login page, th…
The active exploitation of CVE-2026-42945 in NGINX should be treated as an urgent infrastructure risk, especially for internet-facing web servers and reverse proxies. The flaw is a heap buffer overflow in ngx_http_rewrite_module, affecting NGINX versions 0.6.27 through 1.30.0,…
CISA adding CVE-2026-42897 to the Known Exploited Vulnerabilities catalog should be treated as an immediate priority signal for every organization running on-premises Microsoft Exchange. The vulnerability affects Exchange Outlook Web Access and is described as a cross-site scr…
The active exploitation of the Funnel Builder plugin is a serious warning for WooCommerce store owners because this flaw directly impacts checkout security and customer payment data. The vulnerability affects Funnel Builder versions before 3.15.0.3 and allows unauthenticated a…
The active exploitation of the Funnel Builder WordPress plugin is a serious warning for WooCommerce site owners because this is not just a website defacement risk, it directly targets payment data. The flaw affects plugin versions before 3.15.0.3 and can be abused without auth…