Cyber News

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Hackers target Microsoft SharePoint RCE chain with PoC exploit

The SharePoint story is more specific than "RCE chain under attack." Defenders are now dealing with CVE-2026-55040 in the JWT…

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CVE-2026-8452 is no longer a theoretical NetScaler problem. CISA has now ordered federal agencies to fix it by August 29…

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

This campaign is worth attention because it moves dead-drop logic into an FTP welcome banner, which is unusual enough to…

The safety penalty: Reclaiming operational sovereignty in the age of AI

The safety penalty: Reclaiming operational sovereignty in the age of AI

Cisco Talos is making a strategic point that security leaders should not dismiss as thought-leadership filler. If defensive workflows depend…

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

AnonyMousKIT is more than another phishing-kit story because it connects stolen-device monetization to identity abuse. The useful operator detail is…

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

This campaign matters because the attacker is abusing trusted software-distribution infrastructure rather than only throwaway phishing sites. The useful detail…

Hackers breached over 270 Zimbra servers in ongoing attacks

Hackers breached over 270 Zimbra servers in ongoing attacks

CVE-2026-73570 is the kind of email-infrastructure issue that creates immediate cleanup pressure because it combines unauthenticated remote code execution with…

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos is describing a change in attacker workflow, not just another flashy AI label. UAT-10147 appears to be using…

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Keycloak CVE-2026-18963 deserves attention because it attacks the recovery path defenders usually trust when something else goes wrong. If an…

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

The Calix router flaw is useful because it turns a familiar consumer and branch-office assumption upside down. NAT is often…

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers target WordPress sites in miniOrange auth bypass attacks

The miniOrange WordPress SAML issue matters because it is sitting on an identity trust boundary many site owners assume is…

CISA orders urgent patching of actively exploited Zimbra flaw

CISA orders urgent patching of actively exploited Zimbra flaw

CVE-2026-73570 is the kind of email-infrastructure issue that creates immediate cleanup pressure because it combines unauthenticated remote code execution with…

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos is describing a change in attacker workflow, not just another flashy AI label. UAT-10147 appears to be using…