Cisco Email Gateway Zero-Day Gives Remote Attackers Root Control
Cisco is warning that attackers are exploiting a critical Secure Email Gateway zero-day to execute commands as root without authentication. Organizations should isolate management interfaces, apply Cisco’s remediation...
QR-Code Phishing Reaches Record Levels as Attackers Shift Credential Theft to Phones
ESET says QR-code phishing accounted for about 11% of detected phishing email in the first half of 2026, with roughly 100,000 detections per month. By moving victims from...
Hackers Are Turning Plain CSS Into Keyloggers Hidden Inside Everyday Emails
Security researcher Gareth Heyes has demonstrated that ordinary CSS styling code, not JavaScript or malware, can be weaponized to hijack webmail interfaces and capture passwords keystroke by keystroke....
Critical Exim Vulnerability (EXIM-Security-2026-05-01.1): Remote Code Execution via GnuTLS BDAT Flaw — Patch Now
A critical use-after-free vulnerability in Exim mail servers (versions 4.97–4.99.2 with GnuTLS) allows unauthenticated remote attackers to corrupt heap memory and potentially execute arbitrary code. Patch to version...
Exim 4.99.2 Patches Four Vulnerabilities Including Heap Corruption, DNS Crash, and Memory Leaks
The Exim development team has released version 4.99.2 to fix four security vulnerabilities — including a DNS-triggered crash on musl systems (CVE-2026-40684), heap corruption via malformed JSON (CVE-2026-40685),...