Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Dell Secure Connect Gateway Vulnerability: 3 Critical CVEs (CVSS 9.8)
13+ hour, 33+ min ago (27+ words) Let Hackers Forge Admin Access Most enterprise security teams pour their energy into hardening customer-facing apps — and …...
PaperCut AI Swarm Attack Breaches 395 Orgs [2026]
1+ day, 2+ hour ago (416+ words) Silverfort frames the incident as a warning specifically about identity security. Its analysis argues that automated, AI-driven credential harvesting and lateral movement can escalate to domain-admin control far faster than most organizations’ detection and response processes are built to handle,…...
FudModule Rootkit Hides 5 Weeks via CVE-2026-68820
1+ day, 8+ hour ago (300+ words) Lazarus has steadily upgraded FudModule’s delivery mechanism over four years, and the trajectory tells its own story about how APT groups adapt to defender countermeasures. FudModule is the most documented example of an “EDR-killer” rootkit, but it sits inside a…...
The Chain That Opened the Crisis: How SonicWall SMA1000’s First Zero-Day Turned VPN Appliances Into MFA Harvesting Machines
1+ day, 1+ hour ago (129+ words) CVE-2026-15409 chained SSRF and code injection to achieve root on SMA1000 appliances, stealing TOTP MFA seeds and turning the VPN gateway into a persistent surveillance platform. CISA flagged it for ransomware exploitation. We covered the second chain but never the first…...
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
3+ day, 16+ min ago (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler??flaws to its Known Exploited Vulnerabilities catalog
3+ day, 16+ hour ago (345+ words) U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog More Capable AI, Not Enough Guardrails A New Claude 's Sandbox Failure Shows How AI Can Rationalize Real-World Harm U.S. CISA adds Microsoft Windows, N-able…...
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
3+ day, 21+ hour ago (130+ words) oodaloop.com Informing your decisions with actionable intelligence Home > Briefs > Cyber > Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Fortinet RCE flaw exploited to deploy PivotC2 backdoor. Attackers are abusing a heap‑based buffer overflow in FortiOS and FortiSwitchManager to install…...
AI-powered attack exploited PaperCut flaws to hack 395 organizations
3+ day, 19+ hour ago (523+ words) AdaptHealth confirms 4.1 million people exposed in July cyberattack Over 36,000 exposed Plex servers vulnerable to recent flaws AI-powered attack exploited PaperCut flaws to hack 395 organizations Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers IDScan confirms breach tied to 153 million stolen…...
CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks
4+ day, 7+ min ago (351+ words) The flaw affects FortiOS, FortiSwitchManager, and FortiSASE products. It could allow attackers to execute unauthorized code or commands by sending specially crafted packets. CVE-2025-25249 is a heap-based buffer overflow vulnerability. A heap overflow occurs when an application writes more data…...
Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks
3+ day, 23+ hour ago (254+ words) Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions. Check Point’s own research team uncovered the…...