Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

2+ day, 23+ hour ago   (436+ words) Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports. Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug…...

SecurityWeek
securityweek.com > microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

4+ day, 11+ hour ago   (727+ words) Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local…...

SecurityWeek
securityweek.com > adobe-patches-over-170-vulnerabilities-including-commerce-zero-day

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

4+ day, 11+ hour ago   (547+ words) Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score…...

SecurityWeek
securityweek.com > mikrotik-patches-critical-flaws-chained-to-hack-routers

MikroTik Patches Critical Flaws Chained to Hack Routers

4+ day, 19+ hour ago   (570+ words) Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two…...

SecurityWeek
securityweek.com > mathspace-data-breach-exposes-over-1-million-people

Mathspace Data Breach Exposes Over 1 Million People

4+ day, 19+ hour ago   (600+ words) Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance. Mathspace, an online mathematics program for students, has disclosed a data breach that impacts over 1 million individuals. The incident, it says, was discovered last…...

SecurityWeek
securityweek.com > adobe-commerce-zero-day-exploited-to-backdoor-online-stores

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

5+ day, 18+ hour ago   (545+ words) The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec…...

SecurityWeek
securityweek.com > modified-screenconnect-clients-used-in-worm-like-campaign

Modified ScreenConnect Clients Used in Worm-Like Campaign

5+ day, 18+ hour ago   (646+ words) The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. Modified ScreenConnect clients are being used in an attack campaign to spread malicious payloads to other endpoints, cybersecurity firm Huntress warns. The worm-like attacks…...

SecurityWeek
securityweek.com > 12-year-old-postgresql-vulnerability-enables-database-server-takeover

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

1+ week, 1+ day ago   (655+ words) PostgreSQL releases since 2014 contain a severe vulnerability that allows attacker with low privileges to take over databases and servers, cybersecurity firm Cyera reports. An open source relational database system offering support for both relational (SQL) and non-relational (JSON) queries, PostgreSQL…...

SecurityWeek
securityweek.com > malicious-virtualizor-update-served-via-bgp-hijacking

Malicious Virtualizor Update Served via BGP Hijacking

1+ week, 3+ day ago   (737+ words) Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. Softaculous’ Virtualizor users were served malicious software updates for two days after a threat actor diverted internet traffic to attacker-controlled servers. A…...

SecurityWeek
securityweek.com > 23-year-old-sality-p2p-botnet-disrupted

23-Year-Old Sality P2P Botnet Disrupted

1+ week, 3+ day ago   (538+ words) The shutdown operation involved peer list manipulation and Sality payload URL takedown. After 23 years of operation, the Sality peer-to-peer (P2P) botnet has been disrupted as part of an international law enforcement effort. First observed in 2003, Sality has been used for distributing…...