Fortinet Firewalls Under Siege: New PivotC2 Malware Exploits Critical CAPWAP Flaw
A critical, unauthenticated buffer overflow in FortiOS's CAPWAP service is being actively exploited to plant a custom Node.js post-exploitation toolkit dubbed PivotC2. Researchers say at least 178 devices...
Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover
Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...
Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry
Ivanti has disclosed a cluster of vulnerabilities spanning Endpoint Manager Mobile, Neurons for ITSM, and Sentry, several rated up to 9.9 in severity and capable of unauthenticated remote...
Adobe Commerce Stores Face Active StyleSmuggler Zero-Day Attacks With No Official Patch
Attackers are exploiting an unauthenticated remote-code-execution flaw across current Magento Open Source and Adobe Commerce releases. Store operators should treat the incident as an active compromise risk and...
Security Teams Face a Week of Zero-Days, Router Intrusions and AI-Accelerated Attacks
A packed week of security disclosures combined active browser and commerce exploitation with router espionage, identity failures and faster AI-assisted intrusions. Defenders should use the converging signals to...
ZTNA in 2026: Ten Platforms Shaping Secure Access Beyond the Traditional VPN
A new 2026 market overview compares ten prominent zero-trust network access platforms for cloud, hybrid and remote environments. Buyers should look beyond feature checklists and test identity, device...
Microsoft Investigates Windows Teams Startup Failures as Users Turn to Web and Mobile
Some Windows users are seeing Microsoft Teams fail to open or take up to two minutes to load. Microsoft is gathering client logs under incident TM1466820, while web...
AI-Assisted Intruder Reaches Enterprise Root Access in Less Than 10 Hours
An attacker reportedly used frontier models and agentic frameworks to compress a complex enterprise intrusion into less than ten hours. The incident shows how exposed services, embedded secrets...