109Articles
9Categories
2026-04-09Date
🚨
Patch windows collapse as time-to-exploit acceleratesThe gap between vulnerability disclosure and exploitation is drastically decreasing, putting security teams’ patching practices on notice. According to Rapid7’s latest Cyber Threat Landscape Report , confirmed exploitation of newly disclosed high- and critical-severity vulnerabil…
KEV
🚨
What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical InfrastructureAn Iran-affiliated threat group has evolved from defacing water utility displays to deploying custom ICS malware and exploiting Rockwell Automation PLCs across multiple U.S. critical infrastructure sectors. Key takeaways: CyberAv3ngers is a state-directed threat group operating u…
KEV
🐛
Fortinet EMS Zero-Day, Anthropic's AI Finds Thousands of Bugs, Iranian Hackers Target US ICS
KEV
🐛
Palo Alto Cortex XSOAR Flaw in Microsoft Teams Integration Lets Attackers Access Data
🐛
CVE-2026-34933 Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon
🐛
CVE-2026-39314 CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported`
🐛
CVE-2026-31789 Heap Buffer Overflow in Hexadecimal Conversion
🐛
CVE-2026-28387 Potential Use-after-free in DANE Client Code
🐛
CVE-2026-31790 Incorrect Failure Handling in RSA KEM RSASVE Encapsulation
🐛
CVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL
🐛
CVE-2026-34446 ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
🐛
CVE-2026-39316 CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer
🐛
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
🐛
CVE-2026-34445 ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
🐛
CISA Issues Warning on Critical Ivanti EPMM Flaw Exploited in Ongoing Attacks
KEV
🐛
Technical Details Released for Critical Cisco SSM Command Execution Vulnerability
🐛
Vulnerability-Lookup 4.4.0
KEV
🐛
Hackers have been exploiting an unpatched Adobe Reader vulnerability for months
KEV
🐛
VU#536588: Multiple Heap Buffer Overflows in Orthanc DICOM Server
⚠️
Questions raised about how LinkedIn uses the petabytes of data it collects
⚠️
GitLab Addresses Multiple Vulnerabilities Linked to DoS and Code Injection
⚠️
Multiple SonicWall Flaws Enable SQL Injection and Privilege Escalation Attacks
⚠️
Microsoft suspends dev accounts for high-profile open source projects
⚠️
Linux Foundation Leader Impersonated in Slack Attack on Open Source Developers
⚠️
Adobe Reader Zero-Day Exploited for Months: Researcher
⚠️
Weak at the seams
⚠️
Hackers exploiting Acrobat Reader zero-day flaw since December
⚠️
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
⚠️
Critical Vulnerability in Ninja Forms Exposes WordPress Sites - Infosecurity Magazine
⚠️
Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities
⚠️
New ClickFix variant bypasses Apple safeguards with one‑click script execution
⚠️
New Phishing Campaign Exploits Google Storage to Deliver Remcos RAT
⚠️
Attackers Deploy Hidden Magecart Skimmer on Magento Using SVG onload Abuse
⚠️
Hackers Actively Attacking Adobe Reader Users Using Sophisticated 0-Day Exploit
⚠️
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
⚠️
Intent redirection vulnerability in third-party SDK exposed millions of Android wallets to potential risk
⚠️
Microsoft BANNED WireGuard, VeraCrypt & Windscribe With Zero Warning
⚠️
Cloudflare ‘actively adjusting’ quantum priorities in wake of Google warning
⚠️
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
⚠️
Healthcare IT solutions provider ChipSoft hit by ransomware attack
⚠️
AI Makes All Bug Shallow? - PSW #921
⚠️
U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026
⚠️
[webapps] React Server 19.2.0 - Remote Code Execution
⚠️
[webapps] Jumbo Website Manager - Remote Code Execution
⚠️
[local] ZSH 5.9 - RCE
⚠️
Master C and C++ with our new Testing Handbook chapter
📋
Critical Chrome Flaws Let Attackers Execute Arbitrary Code
📋
AI Can Catch Malicious Updates
📢
Microsoft Details How Defender Protects High-Value Assets in Real-World Attacks
📢
The Hidden ROI of Visibility: Better Decisions, Better Behavior, Better Security
📢
STX RAT Hides Remote Desktop, Steals Data to Dodge Detection
📢
Juniper Networks security advisory (AV26-334)
📢
HPE security advisory (AV26-333)
📢
Qualcomm security advisory – April 2026 monthly rollup (AV26-335)
📢
Tenable security advisory (AV26-336)
📢
Elastic on Defence Cyber Marvel 2026: A Technical overview from the Exercise Floor
🔥
Shaky Ceasefire Unlikely to Stop Cyberattacks From Iran-Linked Hackers for Long
🔥
Microsoft Confirms Windows 11 Update Breaks Start Menu Search
🔥
Hackers steal $3.6 million from crypto ATM giant Bitcoin Depot
🔥
300,000 People Impacted by Eurail Data Breach
🔥
China’s Tianjin Supercomputer Center Allegedly Hit in 10-Petabyte Data Theft
🔥
Fake Security Tool Spreads LucidRook in Taiwan Cyberattacks
🔥
Eurail says December data breach impacts 300,000 individuals
🔥
Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access
🔥
Apple Intelligence AI Guardrails Bypassed in New Attack
🔥
Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees
🔥
Eurail says December data breach impacts 300,000 individuals
🔥
Protecting Cookies with Device Bound Session Credentials
🔥
CASI Leaderboard Shifts: Developer Role Attack, and Three Concerning Incidents
🕵️
ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886, (Thu, Apr 9th)
🕵️
Meta Business Alerts Abused for Phishing Campaigns
🕵️
Silver Fox Campaign Spreads ValleyRAT via Fake Chinese Telegram Language Pack
🕵️
$3.6 Million Stolen in Bitcoin Depot Hack
🕵️
RoningLoader Campaign Uses DLL Side-Loading, Code Injection to Slip Past Defenses
🕵️
Package Security Problems for AI Agents
🕵️
LinkedIn Hidden Code Secretly Searches Your Browser for Installed Extensions
🕵️
Google Warns of New Campaign Targeting BPOs to Steal Corporate Data
🕵️
On Microsoft’s Lousy Cloud Security
🕵️
ClickFix Campaign Abuses macOS Script Editor to Deploy Atomic Stealer
🕵️
Iran Disrupts US Critical Infrastructure Via Exposed PLCs
🕵️
Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region
🕵️
13-year-old bug in ActiveMQ lets hackers remotely execute commands
🕵️
Webinar: From noise to signal - What threat actors are targeting next
🕵️
FBI: Cybercrime Losses Neared $21 Billion in 2025 - SecurityWeek
🕵️
Phishing Campaign Impersonates Palo Alto Networks Recruiters
🕵️
Can we Trust AI? No – But Eventually We Must
🕵️
ClickFix, Malicious DMGs Push notnullOSX to macOS Users
🕵️
AI Phishing Attack Prevention Strategies: How AI Identifies and Limits Human Risk
🕵️
U.S. Treasury to loop in crypto sector on hacker warnings shared with traditional firms
🕵️
The agentic SOC—Rethinking SecOps for the next decade
🕵️
New VENOM phishing attacks steal senior executives' Microsoft logins
🕵️
The long road to your crypto: ClipBanker and its marathon infection chain
🕵️
How Phishing Is Targeting Germany’s Economy: Active Threats from Finance to Manufacturing
🌐
Smart Slider updates hijacked to push malicious WordPress, Joomla versions
🌐
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns
🌐
Google Chrome adds infostealer protection against session cookie theft
🌐
New ‘LucidRook’ malware used in targeted attacks on NGOs, universities
🌐
This fake Windows support website delivers password-stealing malware
📡
Number Usage in Passwords: Take Two, (Thu, Apr 9th)
📡
The Hidden Security Risks of Shadow AI in Enterprises
📡
Fake BTS ARIRANG tour tickets: K-pop fans being targeted by scammers | Kaspersky official blog
📡
When attackers already have the keys, MFA is just another door to open
📡
Hacker stole £700,000 from U.K. energy company by redirecting payment
📡
Tearing down a car telematic unit (and finding an accident on Facebook)
📡
Third-Party Risk Is an Intelligence Operation. It's Time We Treated It Like One.
📡
[webapps] RomM 4.4.0 - XSS_CSRF Chain
📡
Scammers pose as Amazon support to steal your account
📡
NSFW app leak exposes 70,000 prompts linked to individual users
📡
30,000 private Facebook images allegedly downloaded by Meta employee