Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
The Chain That Opened the Crisis: How SonicWall SMA1000’s First Zero-Day Turned VPN Appliances Into MFA Harvesting Machines
3+ hour, 32+ min ago (129+ words) CVE-2026-15409 chained SSRF and code injection to achieve root on SMA1000 appliances, stealing TOTP MFA seeds and turning the VPN gateway into a persistent surveillance platform. CISA flagged it for ransomware exploitation. We covered the second chain but never the first…...
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
8+ hour, 34+ min ago (444+ words) A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition during subscription-content restore operations. The…...
Check Point VPN CVE-2026-85102 and CVE-2026-85103: Early Warning for Pre-Authentication RCE
10+ hour, 55+ min ago (1541+ words) 1. Basic Information Original Title: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Source: BleepingComputer, Dutch NCSC, Check Point Published Date: 2026-09-12 Severity: High Basis for Severity: Both CVSS 9.8 vulnerabilities allow unauthenticated remote code execution. Although the reference materials do…...
One Click Away from Account Compromise: What a Recent Microsoft 365 Phishing Campaign Teaches Us
16+ hour, 36+ min ago (352+ words) Phishing is still one of the simplest ways to target an employee. A message does not always look …...
How AI Agents Expand the Identity Security Attack Surface
2+ day, 13+ hour ago (164+ words) Agentic AI, Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development Humans can recognize and reject obviously inappropriate requests, but an inadequately governed agent may simply execute them, said Menlo Security CEO Bill Robbins. See Also: Why Traditional DLP Can't Keep…...
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler??flaws to its Known Exploited Vulnerabilities catalog
2+ day, 18+ hour ago (345+ words) U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog More Capable AI, Not Enough Guardrails A New Claude 's Sandbox Failure Shows How AI Can Rationalize Real-World Harm U.S. CISA adds Microsoft Windows, N-able…...
The Next CX Security Risk May Be the AI Agent You Gave Access
2+ day, 19+ hour ago (871+ words) Home → Security, Privacy & Compliance Anthropic, Concentrix, Zscaler, Proofpoint and OpenAI reveal how AI agents are reshaping enterprise security, access and customer experience risk Enterprise AI is gaining access to the systems that make customer experiences work, while security teams are…...
Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
3+ day, 9+ min ago (707+ words) Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections. The campaign starts with calls and texts to employees. Attackers pose as IT support, claim a passkey, MFA, or single…...
CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks
3+ day, 9+ min ago (324+ words) CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must apply vendor mitigations by September 12, 2026. CVE-2026-19490 affects Citrix NetScaler ADC and NetScaler Gateway…...
NextGen Mirth Connect Flaws Expose Downstream System Logins
2+ day, 21+ hour ago (695+ words) Health records storage vendor NextGen Connect has a batch of high-severity flaws that could let attackers walk away with administrator passwords that open access to databases and downstream systems the logins connect to, an independent researcher found. See Also: What…...