Coordinated Cyberattacks Target U.S. Water Systems
Beginning July 26th, coordinated cyberattacks targeting U.S. water systems—attributed to Iranian hackers and other nation-state actors—have disrupted service in multiple states, exploiting weak.
Beginning July 26th, coordinated cyberattacks targeting U.S. water systems—attributed to Iranian hackers and other nation-state actors—have disrupted service in multiple states, exploiting weak.
CISA has added three vulnerabilities – Langflow RCE, Apache Tomcat encryption bypass, and N-able N-central authentication bypass – to its KEV catalog due to active exploitation. Federal agencies must.
Coordinated cyberattacks targeting municipal water systems in at least seven U.S. states have prompted federal warnings and boil-water notices, with suspected Iranian involvement highlighting the.
A public exploit has been released for a pre-authentication remote code execution (RCE) vulnerability in vBulletin. Unauthenticated attackers can now execute arbitrary PHP code on vulnerable forums,.
Attackers are actively exploiting a critical remote code execution (RCE) vulnerability in Alibaba’s Fastjson 1.x library, CVE-2026-16723. The unpatched flaw affects versions 1.2.68 through 1.2.83 and.
A sophisticated malware campaign has been discovered abusing legitimate Google Chrome enterprise policy keys to hijack user browsers, bypassing security measures with DLL side-loading techniques.
A supply chain attack targeting Klue has exposed sensitive customer data and disrupted integrations with Salesforce and other platforms. The ‘Icarus’ threat actor exploited a compromised legacy.
A critical server-side request forgery (SSRF) vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager is being actively exploited to deploy webshells and achieve root access. Patches.
ShinyHunters claims to have stolen a massive 8.8TB of data from One Medical, Amazon’s healthcare provider, threatening release unless negotiations begin by June 22nd. The breach reportedly involves.
A sophisticated malware campaign is using WhatsApp to distribute malicious Visual Basic Script (VBS) files targeting Windows users across multiple countries. The attack, which began in late February.