Topic: security advisories
-
Windows IKE Extension RCE Flaw Actively Exploited
CISA warns that threat actors are actively exploiting CVE-2024-38063, a critical 9.8-severity remote code execution vulnerability in Windows IKE Service Extensions, which allows unauthenticated attackers to take full control of systems without user interaction. Microsoft patched the flaw in its A...
Read More » -
Former Medusa Affiliate Deploys New StormEncryptor Ransomware
Microsoft's threat intelligence unit tracks Storm-1175, a China-based actor previously linked to Medusa ransomware, which has now deployed a new custom C++ locker called StormEncryptor that appends ".encrypted" to files and demands payment within 72 hours. The group's recent intrusions likely exp...
Read More » -
Cisco IMC root flaw now has public PoC exploit (CVE-2026-20200)
Cisco patched CVE-2026-20200, a critical 9.8-severity flaw in its Integrated Management Controller (IMC) that allows low-privileged, authenticated attackers to execute root commands via the web interface; a public proof-of-concept exploit (CIMCown) is already available. Cisco also released harden...
Read More » -
N-able N-central flaw exploited to hit managed endpoints (CVE-2026-18577)
Attackers are actively exploiting CVE-2026-18577, an authentication bypass in N-able N-central's on-premises versions, by seizing admin accounts and using the Take Control feature to access managed endpoints, where they install Cloudflare tunnels for persistence. Over half (55.6%) of reachable N-...
Read More » -
Cisco FMC Flaw Exploited in Attacks (CVE-2026-20316)
CVE-2026-20316, a static credential vulnerability in Cisco's Secure Firewall Management Center (FMC), is under active exploitation and has been added to CISA's Known Exploited Vulnerabilities catalog, requiring urgent patching. The flaw allows attackers to bypass authentication and potentially ac...
Read More » -
AI Bug Hunting Drives Record Microsoft Patch Tuesday
Microsoft's July 2026 Patch Tuesday is a record-breaking security release, fixing over 570 vulnerabilities, including two flaws (CVE-2026-56155 and CVE-2026-56164) already under active exploitation and a previously disclosed issue (CVE-2026-50661) now receiving a patch. The surge in patches is dr...
Read More » -
Google, Apple Issue Emergency Patches for Zero-Day Exploits
Google and Apple issued emergency patches for actively exploited zero-day vulnerabilities, highlighting the threat from advanced, likely state-sponsored hacking operations. The vulnerabilities were identified through a joint effort by Apple's security team and Google's Threat Analysis Group, whic...
Read More » -
Urgent Microsoft Update: Patch Windows 10, 11, Server Now
Microsoft has urgently patched a zero-day vulnerability (CVE-2025-62215) in the Windows Kernel, which is already being actively exploited to gain system-level privileges. The flaw involves improper synchronization in concurrent execution, allowing attackers to escalate privileges after initial ac...
Read More » -
Malicious 'IndonesianFoods' Worm Floods npm With 100K Packages
A self-propagating npm package called 'IndonesianFoods' has flooded the registry with over 100,000 junk packages, using random Indonesian names and food terms, though they currently contain no harmful code. The attack aims to overwhelm security systems and disrupt the software supply chain, with ...
Read More » -
Critical runC Flaws Let Hackers Escape Docker Containers
Three critical vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) in runC allow attackers to escape Docker and Kubernetes containers and gain root access to the host system by exploiting flaws in bind mounts and symbolic link handling. Successful exploitation requires starting conta...
Read More » -
QNAP Patches Critical Zero-Day Flaws Exploited at Pwn2Own
QNAP has urgently patched seven critical zero-day vulnerabilities exploited during the Pwn2Own Ireland 2025 contest, affecting core components like QTS/QuTS hero operating systems and applications such as Hyper Data Protector and HBS 3. The company advises users to install the latest software upd...
Read More » -
Microsoft GoAnywhere Flaw Fuels Ransomware Attacks
A critical vulnerability (CVE-2025-10035) in Fortra's GoAnywhere MFT platform is being exploited by ransomware attackers, allowing remote access without user interaction. The cybercrime group Storm-1175, linked to Medusa ransomware, is actively using this flaw to gain initial access, deploy remot...
Read More » -
Networking Devices Still at Risk from Pixie Dust Attacks
A decade-old security flaw known as the pixie dust attack continues to threaten networks by exploiting weaknesses in the Wi-Fi Protected Setup (WPS) protocol, allowing unauthorized access through brute-forcing the PIN in seconds. Recent analysis of 24 networking devices found that only four were ...
Read More » -
Microsoft, Adobe, SAP Issue Critical September 2025 Patch Tuesday Updates
The September 2025 Patch Tuesday included critical security updates from Microsoft, Adobe, and SAP, addressing numerous vulnerabilities not currently under active exploitation. Microsoft patched over 80 flaws, including a privilege escalation issue in Windows NTLM and a high-risk remote code exec...
Read More »