62Articles
8Categories
2026-02-25Date
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its  Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.  CVE-2022-20775  Cisco Catalyst SD-WAN Path Traversal Vulnerability CVE-2026-20127  Cisco Cat…
KEV
πŸ›
Discord Finds Age Identification May Have Privacy Concerns
πŸ›
Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
KEV
πŸ›
SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution
πŸ›
CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability
KEV
πŸ›
CISA and Partners Release Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems
KEV
πŸ›
CVE-2026-27199 Werkzeug safe_join() allows Windows special device names
πŸ›
CVE-2026-2739 This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.
πŸ›
CVE-2026-26960 node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction
πŸ›
CVE-2026-27211 Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse
πŸ›
CVE-2023-53543 vdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check
πŸ›
Five Eyes issue emergency directive on exploited Cisco SD-WAN zero-day
KEV
πŸ›
ZDI-26-132: Siemens SINEC NMS Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-131: Siemens SINEC NMS Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-130: IceWarp collaboration Directory Traversal Information Disclosure Vulnerability
πŸ›
ZDI-26-129: Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability
πŸ›
ZDI-26-128: (Pwn2Own) Ubiquiti Networks AI Pro Uncaught Exception Denial-of-Service Vulnerability
πŸ›
ZDI-26-127: (Pwn2Own) Ubiquiti Networks AI Pro Cleartext Transmission Information Disclosure Vulnerability
πŸ›
ZDI-26-126: (Pwn2Own) Ubiquiti Networks AI Pro Discovery Protocol Missing Encryption Protocol Downgrade Vulnerability
πŸ›
ZDI-26-125: Docker Desktop grpcfuse Kernel Module Out-Of-Bounds Read Information Disclosure Vulnerability
πŸ›
ZDI-26-124: claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability
⚠️
Medical device maker UFP Technologies warns of data stolen in cyberattack
⚠️
The OpenClaw Hype: Analysis of Chatter from Open-Source Deep and Dark Web
⚠️
Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries
⚠️
Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration
⚠️
Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker
⚠️
RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN
⚠️
US cybersecurity agency CISA reportedly in dire shape amid Trump cuts and layoffs
⚠️
Inside the story of the US defense contractor who leaked hacking tools to Russia
⚠️
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
⚠️
Microsoft warns of job‑themed repo lures targeting developers with multi‑stage backdoors
⚠️
Boards don’t need cyber metrics β€” they need risk signals
⚠️
Bake Security In Early
⚠️
VMware Aria Operations Vulnerability Could Allow Remote Code Execution - SecurityWeek
⚠️
Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign
⚠️
mquire: Linux memory forensics without external dependencies
⚠️
Risky Business #826 -- A week of AI mishaps and skulduggery
πŸ“’
Immediate Action Required: CISA Issues Emergency Directive to Secure Cisco SD-WAN Systems
πŸ“’
Governing AI with Security Fundamentals
πŸ“’
Infinite AI Monkeys, Ploutus, Serv-U, Fortinet, Cyberwar, COBOL, NIST, Aaran Leyland - SWN #558
πŸ”₯
Poisoning AI Training Data
πŸ”₯
Chinese cyberspies breached dozens of telecom firms, govt agencies
πŸ”₯
Marquis sues SonicWall over backup breach that led to ransomware attack
πŸ”₯
Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware
πŸ”₯
Canadian Tire - 38,306,562 breached accounts
πŸ•΅οΈ
ISC Stormcast For Wednesday, February 25th, 2026 https://isc.sans.edu/podcastdetail/9824, (Wed, Feb 25th)
πŸ•΅οΈ
Google Reports On Adversarial Use of AI in Late 2025
πŸ•΅οΈ
News alert: One Identity fills CFO-COO role to strengthen operating discipline amid expansion
πŸ•΅οΈ
Ukrainian convicted for helping fake North Korean IT workers
πŸ•΅οΈ
The SOC Is Now Agentic β€” Introducing the Next Evolution of Cortex
πŸ•΅οΈ
Variations of the ClickFix | Kaspersky official blog
πŸ•΅οΈ
Security as a Business Enabler by Re-envisioning Risk and Leading through Uncertainty - BSW #436
πŸ•΅οΈ
What are You Working on Wednesday
πŸ•΅οΈ
Malicious NuGet Package Targets Stripe Developers - Infosecurity Magazine
πŸ•΅οΈ
ShinyHunters leak 12.4M CarGurus records after ransom threat
πŸ•΅οΈ
Phishing campaign targets freight and logistics orgs in the US, Europe
🌐
Fake Next.js job interview tests backdoor developer's devices
πŸ“‘
Weekly Threat Bulletin – February 25th, 2026
πŸ“‘
SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks
πŸ“‘
Top 5 Ways Broken Triage Increases Business Risk Instead of Reducing It
πŸ“‘
Manual Processes Are Putting National Security at Risk
πŸ“‘
$10,000 bounty offered if you can hack Ring cameras to stop them sharing your data with Amazon