Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
“The attack email contained a message impersonating an MS account security alert,” the Genians Security Center (GSC) said. “It was designed to create concern over possible
iRhythm discloses data breach, says hackers stole patient info
Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks
Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write.
The post Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks appeared first on SecurityWeek.
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0.
“A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or
CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case of privilege
DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
SimpleHelp bug lets hackers create rogue remote support accounts
Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
The way in was a backdoor on their REDCap research servers that stole login credentials. The exfiltration was the unusual part: the attackers rewired the victims’ own Google Workspace rules to copy any message
North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
According to a report published by Proofpoint, the threat actor has been found orchestrating phishing campaigns using developer role recruitment or code review themes
