China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
“The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale,” Lumen’s
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It’s tracked as CVE-2026-25089 (CVSS score: 9.1).
“An
Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
The vulnerability in question is CVE-2026-5027 (CVSS score: 8.8), a case of path traversal that could allow an attacker to write files to arbitrary locations.
“The ‘POST /
China-linked JDY botnet expands targeting of U.S. military networks
CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
The list of vulnerabilities is as follows –
CVE-2026-20245 (CVSS score: 7.8) – An improper encoding or escaping of output vulnerability in Cisco Catalyst SD-WAN Manager that could allow an
The 5 Best Practices for Secure Identity Verification
Infostealers Turn Millions of Devices Into Credential Theft Machines
As attackers increasingly favor stolen credentials over exploits, infostealers have become a primary source of access for ransomware and other cybercrime operations.
The post Infostealers Turn Millions of Devices Into Credential Theft Machines appeared first on SecurityWeek.
Cyera Raises $600 Million at $12 Billion Valuation
Cyera is positioned as one of the most valuable privately held cybersecurity firms in the world with total funding topping $2 billion.
The post Cyera Raises $600 Million at $12 Billion Valuation appeared first on SecurityWeek.
