Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
PaperCut MF/NG auth bypass and RCE vulnerabilities under attack
Two recently disclosed vulnerabilities in PaperCut MF/NG — CVE-2026-81578 (authentication bypass, CVSS v4.0: 8.8) and CVE-2026-82078 (remote code execution, CVSS ...
RCE Attacks via Super Forms and Elementor Pro File Upload Bugs
Two critical vulnerabilities in the popular WordPress plugins Super Forms (CVE-2026-14894, CVSS 9.8) and Elementor Pro (CVE-2026-32475, CVSS 9.8) are ...
CVE-2026-85046: Actively Exploited V8 Zero-Day in Google Chrome
On September 3, 2026, Google released an update to the stable Chrome channel for desktop platforms, addressing 12 vulnerabilities, including ...
Guidance on Cisco Nexus 9000 and IOS XR Security Updates
On 2 September 2026, Cisco released patches for critical vulnerability CVE-2026-20212 (CVSS 9.8) in ten Silicon One–based Nexus 9000 switch ...
How BraZetsu Turns Infected Hosts into an Underground Marketplace Asset
Researchers at Group-IB have published a report on the modular malicious framework BraZetsu — a Python-based tool for Windows that ...
Critical SonicWall SMA 1000 Vulnerabilities Exploited in the Wild
SonicWall has confirmed active exploitation of multiple vulnerabilities in Secure Mobile Access (SMA) 1000 series devices — enterprise VPN gateways ...
AI Infrastructure Targeted as CISA Adds New KEV Vulnerabilities
On September 2, 2026, CISA added seven vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, confirming their active exploitation. Affected ...
FalconFlank, HardBreacher and ShieldBreak PoCs Against Endpoint Security
The security researcher known under the alias MSNightmare (INFINITE NIGHTMARE) has published on GitHub a public PoC exploit called FalconFlank, ...
How Frontier AI Cybersecurity Models Became Both Shield and Threat
In early September 2026, the three largest AI developers — Google, Anthropic and OpenAI — almost simultaneously unveiled specialized cybersecurity ...