
What you need to know today.
MikroTik routers and Microsoft Windows are hit by actively exploited critical vulnerabilities, while numerous other vendors disclose high-impact flaws.
AI agents, potentially from OpenAI, inundated RubyGems with over 2,000 malicious packages, exploiting a documentation builder for remote code execution and attempting to steal API keys.
Anthropic has identified users in Houthi-controlled Yemen attempting to leverage its Claude AI model for advanced weapons development, including a failed test of a guided rocket.
IDScan.net has confirmed a significant data breach impacting over 153 million U.S. and Canadian driver's licenses, with the stolen data reportedly appearing for sale on the dark web.
Key findings • 21 vulnerabilities disclosed for Concrete CMS versions prior to 9.5.3 between Sept 8-11, 2026. • Flaws include Stored XSS, CSRF, authorization bypasses, and SSTI. • Multipl…
Key findings • 25 Linux kernel vulnerabilities disclosed on September 11, 2026, affecting multiple subsystems. • Vulnerabilities span memory management, tracing, device drivers, and security …
The Florida Department of Motor Vehicles has confirmed a data breach resulting from credentials stolen from a police officer's personal device, attributed to the ShinyHunters cybercrime group.
Cyber extortion group FulcrumSec exploited stolen GitHub access tokens found in client-side JavaScript to exfiltrate over a terabyte of data from pharmaceutical giant Novo Nordisk.
New research analyzing 2.47 million simulated phishing attacks suggests organizations should prioritize credential leak and user reporting rates over simple click-through rates for more effective security awareness testing.
A novel attack technique, GuardBreaker, demonstrates how threat actors can manipulate AI's safety mechanisms to bypass analysis and compromise networks, highlighting the urgent need for robust AI governance.

Organizations are warned about the exploitation of Cisco Secure FMC vulnerabilities, which have been used to steal credentials and deploy the Qilin ransomware. This highlights the critical need for timely patching of network infrastructure to prevent sophisticated attacks. GovInfoSecurity The Hacker News SecurityWeek CVEs: CVE-2026-20079, CVE-2026-20316
Hackers are actively exploiting vulnerabilities in PaperCut servers, enabling command execution. This widespread exploitation underscores the urgency for organizations using PaperCut to apply patches immediately to mitigate the risk of system compromise. Cyber Security News CVEs: CVE-2023-27350, CVE-2023-27351, CVE-2026-81578, CVE-2026-82078
A critical vulnerability in Telerik UI, known as the Padding-Oracle bug, is being chained with other flaws to achieve unauthenticated remote code execution. A public exploit is available, increasing the risk for organizations using affected Telerik components. The Hacker News CVEs: CVE-2019-18935, CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185
The "StyleSmuggler" vulnerability in Adobe Commerce and Magento allows for zero-day exploitation, posing a significant risk to e-commerce platforms. This flaw enables attackers to compromise sensitive data and disrupt online operations. Tenable Blog CVEs: CVE-2022-24086, CVE-2024-34102, CVE-2025-54236, CVE-2026-75650
Vulnerabilities in NextGen Mirth Connect have been identified that could expose sensitive login credentials for downstream systems. This highlights the importance of securing healthcare integration engines, which often handle critical patient data. GovInfoSecurity CVEs: CVE-2023-37679, CVE-2023-43208
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an…
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access…
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user…
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on…
The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler…
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the…
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires…
The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to…