Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
3+ hour, 43+ min ago (997+ words) This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven cyberattacks, browser and firewall zero-days, and…...
Bitcoin Lightning Development Kit v0.2.6 Fixes Fund Theft and Restart Bugs
14+ hour, 41+ min ago (333+ words) Lightning Development Kit, a toolkit for building Bitcoin Lightning applications, released v0.2.6 on Sept. 9 with fixes for bugs that could divert small amounts of a node’s funds or prevent saved channel state from loading. LDK packages a Lightning implementation as a…...
Apple's Last Actively Exploited Bug Disclosure Was iOS 26.2, Nine Months Ago
11+ hour, 22+ min ago (203+ words) The most recent Apple security document to say a bug may have been exploited is iOS 26.2, published December 12, 2025. Both flagged issues sat in WebKit, and Apple credited Google’s Threat Analysis Group on each one. Six Apple releases since then, running…...
Dell Secure Connect Gateway Vulnerability: 3 Critical CVEs (CVSS 9.8)
8+ hour, 53+ min ago (27+ words) Let Hackers Forge Admin Access Most enterprise security teams pour their energy into hardening customer-facing apps — and …...
PaperCut AI Swarm Attack Breaches 395 Orgs [2026]
21+ hour, 51+ min ago (416+ words) Silverfort frames the incident as a warning specifically about identity security. Its analysis argues that automated, AI-driven credential harvesting and lateral movement can escalate to domain-admin control far faster than most organizations’ detection and response processes are built to handle,…...
FudModule Rootkit Hides 5 Weeks via CVE-2026-68820
1+ day, 3+ hour ago (300+ words) Lazarus has steadily upgraded FudModule’s delivery mechanism over four years, and the trajectory tells its own story about how APT groups adapt to defender countermeasures. FudModule is the most documented example of an “EDR-killer” rootkit, but it sits inside a…...
iOS 18.7.10: About 120 Security Fixes for iPhone XS and Three Other Devices
1+ day, 4+ hour ago (276+ words) iOS 18.7.10 and iPadOS 18.7.10, released August 17, 2026, list on the order of 120 CVE entries across more than 30 components, according to Apple’s own support article at support.apple.com/en-us/148287. The release is available for exactly four devices: iPhone XS, iPhone XS Max,…...
The Chain That Opened the Crisis: How SonicWall SMA1000’s First Zero-Day Turned VPN Appliances Into MFA Harvesting Machines
20+ hour, 53+ min ago (129+ words) CVE-2026-15409 chained SSRF and code injection to achieve root on SMA1000 appliances, stealing TOTP MFA seeds and turning the VPN gateway into a persistent surveillance platform. CISA flagged it for ransomware exploitation. We covered the second chain but never the first…...
Check Point VPN CVE-2026-85102 and CVE-2026-85103: Early Warning for Pre-Authentication RCE
1+ day, 4+ hour ago (1541+ words) 1. Basic Information Original Title: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Source: BleepingComputer, Dutch NCSC, Check Point Published Date: 2026-09-12 Severity: High Basis for Severity: Both CVSS 9.8 vulnerabilities allow unauthenticated remote code execution. Although the reference materials do…...
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
2+ day, 19+ hour ago (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...