MikroTik RouterOS Flaw Under Active Attack Grants Unauthenticated Shell Access
Attackers are exploiting a RouterOS weakness that can reportedly provide unauthenticated shell access through exposed services, including SSH. MikroTik users should install the fixed releases now, audit every...
Critical ASUS Control Center Chain Opens Managed Fleets to Root Takeover
A CVSS 10.0 flaw chain in ASUS Control Center Enterprise can reportedly give an unauthenticated network attacker a root shell and control of centrally managed devices. Organizations should...
CrowdStrike Unveils SafeMind Agents to Pit Automated Defense Against AI-Driven Attacks
CrowdStrike has introduced SafeMind, a purpose-built family of offensive and defensive AI models designed around Falcon telemetry and incident-response knowledge. The company says the system can improve detection...
Phishing Campaign Chains Google Services to Conceal Credential Theft
A phishing operation is routing victims through legitimate Google services before sending them to personalized credential traps or unauthorized ScreenConnect installers. The technique weakens domain-reputation defenses and hides...
Mathspace Breach Exposes Data of More Than One Million Users
Mathspace says attackers exploited a maximum-severity Metabase flaw and downloaded records belonging to 1,079,819 users. A missed vulnerability alert and incomplete post-patch checks allowed the intrusion to remain...
Stealth Linux Rootkit Hides Fileless Web Shells Inside F5 BIG-IP Memory
Researchers have uncovered a Linux rootkit that alters PHP code only in memory on compromised F5 BIG-IP APM appliances. Its fileless web shell, local socket backdoor and upgrade...
Bimbo Bakeries Employee Data Stolen Through Oracle EBS Zero-Day
Bimbo Bakeries USA says attackers obtained employee names and Social Security numbers through a vendor’s vulnerable Oracle E-Business Suite environment. The disclosure connects another major organization to a...
Roundcube Patches a Dozen Flaws, Including a Zero-Click Webmail XSS and an IPv6-Based SSRF Bypass
The Roundcube team has shipped versions 1.6.19 and 1.7.4 to close twelve security holes, headlined by a stored cross-site scripting bug that fires the moment a crafted email...