CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys

Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and why now The… Continue reading CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE). About CVE-2026-76460… Continue reading Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger is hi… Continue reading Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)

A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by attackers, the backup and recovery company warns. “Exploitation of this vul… Continue reading Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s Product Security Incident Response Team became aware of active exploitat… Continue reading Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Fire… Continue reading Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Another “new normal” is the anonymous security researc… Continue reading September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

Trezor customers hit with phishing calls and letters after shipping-partner breach

Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed. “The leaked information c… Continue reading Trezor customers hit with phishing calls and letters after shipping-partner breach

Thomson Reuters reveals breach that exposed U.S. and Canadian court records

Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and C… Continue reading Thomson Reuters reveals breach that exposed U.S. and Canadian court records