Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Swi… Continue reading Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)→

SonicWall SMA 1000 appliances under attack via zero-day flaws

Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series i… Continue reading SonicWall SMA 1000 appliances under attack via zero-day flaws→

CISA review makes the case for eliminating vulnerability classes

For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categ… Continue reading CISA review makes the case for eliminating vulnerability classes→

Attackers plant remote access tools on compromised PaperCut servers

The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to… Continue reading Attackers plant remote access tools on compromised PaperCut servers→

Unpatched PaperCut NG/MF vulnerability is under active attack

A yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today. “We are aware of confirmed customer incidents and are treating this matter with the … Continue reading Unpatched PaperCut NG/MF vulnerability is under active attack→

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contai… Continue reading Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)→

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platfo… Continue reading Unpatched Zimbra servers are falling to CVE-2026-73570 attacks→

Suspected Iran-linked attack knocked UK power plant offline for days

News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attac… Continue reading Suspected Iran-linked attack knocked UK power plant offline for days→

CISA’s logging guidance works beyond government

The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what ha… Continue reading CISA’s logging guidance works beyond government→