Unpatched PaperCut NG/MF vulnerability is under active attack

A yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today. “We are aware of confirmed customer incidents and are treating this matter with the … Continue reading Unpatched PaperCut NG/MF vulnerability is under active attack

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contai… Continue reading Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platfo… Continue reading Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Suspected Iran-linked attack knocked UK power plant offline for days

News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attac… Continue reading Suspected Iran-linked attack knocked UK power plant offline for days

CISA’s logging guidance works beyond government

The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what ha… Continue reading CISA’s logging guidance works beyond government

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and nee… Continue reading Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulner… Continue reading Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Metabase zero-day exploited to access Framework customer data

Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notificat… Continue reading Metabase zero-day exploited to access Framework customer data

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the… Continue reading N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)

Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface. The fix was part of Cisco’s August 5 advisory … Continue reading Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)