Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > organizations-warned-of-cisco-secure-fmc-exploitation

Organizations Warned of Cisco Secure FMC Exploitation

3+ day, 2+ hour ago   (578+ words) Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year. The security hole,…...

SecurityWeek
securityweek.com > fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

3+ day, 5+ hour ago   (436+ words) Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports. Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug…...

SecurityWeek
securityweek.com > ai-is-giving-lesser-resourced-attackers-nation-state-level-reach-google-warns

AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

3+ day, 19+ hour ago   (731+ words) Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG. Adversaries, both criminal and state-sponsored, are increasingly using AI to automate and scale their attacks, according to Google’s Threat Intelligence Group (GTIG). What…...

SecurityWeek
securityweek.com > new-phishing-attack-creates-malicious-pages-inside-the-victims-browser

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

4+ day, 2+ hour ago   (434+ words) Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. Future phishing campaigns may no longer involve a detectable physical web page. The attack flow…...

SecurityWeek
securityweek.com > hackers-return-263-million-stolen-from-liquid-network

Hackers Return $263 Million Stolen From Liquid Network

4+ day, 19+ hour ago   (553+ words) Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix. Alleged ‘white-hat’ hackers have returned 3,400 Bitcoin (worth approximately $262.6 million) of the 4,000 Bitcoin (~$320 million) stolen from the Bitcoin sidechain Liquid Network over the weekend. The Blockstream-developed sidechain disclosed…...

SecurityWeek
securityweek.com > mikrotik-patches-critical-flaws-chained-to-hack-routers

MikroTik Patches Critical Flaws Chained to Hack Routers

5+ day, 1+ hour ago   (570+ words) Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two…...

SecurityWeek
securityweek.com > adobe-commerce-zero-day-exploited-to-backdoor-online-stores

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

6+ day, 29+ min ago   (545+ words) The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec…...

SecurityWeek
securityweek.com > modified-screenconnect-clients-used-in-worm-like-campaign

Modified ScreenConnect Clients Used in Worm-Like Campaign

6+ day, 48+ min ago   (646+ words) The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. Modified ScreenConnect clients are being used in an attack campaign to spread malicious payloads to other endpoints, cybersecurity firm Huntress warns. The worm-like attacks…...

SecurityWeek
securityweek.com > in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

1+ week, 1+ day ago   (780+ words) Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. Here are this week’s highlights: Microsoft releases cloud patches Microsoft has released patches…...

SecurityWeek
securityweek.com > hpe-patches-critical-rce-vulnerabilities-in-aos-cx

HPE Patches Critical RCE Vulnerabilities in AOS-CX

1+ week, 1+ day ago   (479+ words) Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in the Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical-severity remote code execution (RCE) flaws. Per HPT’s advisory, more than 150 flaws were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these bugs are…...