CISA Adds Exploited Citrix NetScaler Authentication Bypass to Urgent Fix List
CISA has added CVE-2026-19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog. Internet-facing ADC and Gateway deployments supporting remote access should apply Citrix updates...
State-Backed Hackers Exploit Cisco Firewall Flaws for Root Access and Malware Deployment
Attackers are actively abusing two Cisco Secure Firewall Management Center vulnerabilities, including a maximum-severity authentication bypass. Cisco says state-sponsored operators and a ransomware affiliate have used the flaws...
Phishing Campaign Builds Fake Login Pages Inside Browsers After Trusted Microsoft Redirects
A phishing campaign chains DocuSign-themed calendar invitations, Microsoft redirects and browser blob URLs to display credential-stealing pages assembled in local memory. The method reduces reliance on a conventional...
ClearFake CAPTCHA Campaign Disables EDR to Deploy Crypto Stealer
ClearFake has expanded its fake CAPTCHA operation with a vulnerable-driver technique that terminates endpoint defenses before deploying a cryptocurrency stealer. The campaign combines compromised sites, blockchain-hosted instructions, WebDAV...
AI Agent Swarm Exploits PaperCut Flaws Across 440 Servers Worldwide
A Russian-speaking operator used hundreds of autonomous AI agents to compromise 440 PaperCut servers across 48 countries. Although only a fraction reached domain administrator, the campaign shows how...
BlueMoon Exploit Kit Chains Chrome and Windows Zero-Days in Espionage Attacks
Multiple espionage groups are using the BlueMoon exploit kit to chain Chrome and Windows flaws against government, defense and commercial targets. The campaign highlights the danger of patch-gap...
Fake Job Interviews Deliver NodeRabbit and PollCat Malware to Software Developers
An Iran-linked group tracked as Mirage Kitten (UNC1549) is posing as recruiters on LinkedIn to trick developers into running malicious take-home coding tests. The booby-trapped projects deploy two...
Veradigm Discloses Patient SSNs Exposed After Vendor Credentials Were Stolen
Healthcare technology firm Veradigm has disclosed to the SEC that stolen vendor credentials were used to access an API and download patient data, including Social Security numbers. The...