FortiGate Exploitation Campaign Plants PivotC2 Malware and Steals Network Credentials
Attackers are exploiting a critical Fortinet vulnerability to install a custom Node.js remote-access framework on exposed appliances. The campaign has reportedly compromised 178 devices and can harvest credentials,...
ChatGPT Sandbox Isolation Flaw Created a Hidden Route for Cross-Account Data Theft
Researchers found that a shared internal package service could act as a covert communication channel between isolated ChatGPT containers. The proof of concept combined hidden instructions and connected-app...
Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover
Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...
Fortinet Firewalls Under Siege: New PivotC2 Malware Exploits Critical CAPWAP Flaw
A critical, unauthenticated buffer overflow in FortiOS's CAPWAP service is being actively exploited to plant a custom Node.js post-exploitation toolkit dubbed PivotC2. Researchers say at least 178 devices...
Microsoft’s September Patch Tuesday Closes 973 Holes, Including Two Zero-Days Already Under Attack
Microsoft's September 2026 security update addresses 973 vulnerabilities — one of its largest releases on record — including two Windows elevation-of-privilege flaws that attackers are actively exploiting. Several...
How a Shared ChatGPT Sandbox Turned Into a Covert Channel for Stealing Gmail Data
Check Point Research found that ChatGPT's supposedly isolated code-execution sandboxes all shared access to the same backend package repository, allowing hidden instructions to hop between completely unrelated user...
Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry
Ivanti has disclosed a cluster of vulnerabilities spanning Endpoint Manager Mobile, Neurons for ITSM, and Sentry, several rated up to 9.9 in severity and capable of unauthenticated remote...
Adobe Commerce Stores Face Active StyleSmuggler Zero-Day Attacks With No Official Patch
Attackers are exploiting an unauthenticated remote-code-execution flaw across current Magento Open Source and Adobe Commerce releases. Store operators should treat the incident as an active compromise risk and...