Check Point Confirms In-the-Wild Attacks on Critical Management Server Zero-Day
A critical, pre-authentication flaw in Check Point's Management Server software was exploited in the wild weeks before a fix existed, letting attackers upload and run code on systems...
CISA Orders Urgent ScreenConnect Response as Attackers Exploit Critical Flaw
CISA has confirmed active exploitation of a critical ConnectWise ScreenConnect authorization flaw and ordered rapid remediation for covered agencies. Organizations should patch immediately and investigate prior remote sessions,...
Chinese Hacking Crew Weaponizes Critical Gitea Flaw to Hijack Self-Hosted Git Servers Worldwide
A Chinese-speaking intrusion set tracked as Red Heron is exploiting a critical remote-code-execution bug in self-hosted Gitea instances, deploying a custom Linux implant and rootkit against victims in...
CISA Flags CVSS 10 GitLab File-Read Flaw Under Active Attack
CISA says attackers are exploiting a critical GitLab path-traversal vulnerability that can expose arbitrary server files without authentication. Organizations should patch immediately, review access logs, and treat exposed...
State-Backed Hackers Exploit Cisco Firewall Flaws for Root Access and Malware Deployment
Attackers are actively abusing two Cisco Secure Firewall Management Center vulnerabilities, including a maximum-severity authentication bypass. Cisco says state-sponsored operators and a ransomware affiliate have used the flaws...
CISA Adds Exploited Citrix NetScaler Authentication Bypass to Urgent Fix List
CISA has added CVE-2026-19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog. Internet-facing ADC and Gateway deployments supporting remote access should apply Citrix updates...
MikroTik RouterOS Flaw Under Active Attack Grants Unauthenticated Shell Access
Attackers are exploiting a RouterOS weakness that can reportedly provide unauthenticated shell access through exposed services, including SSH. MikroTik users should install the fixed releases now, audit every...