Cybersecurity news and vulnerability intelligence
Cybersecurity news from leading outlets and government advisories in one place, linked to the CVEs they cover, with patch priority, exploitation data and spike alerts.
Latest stories
- Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports SecurityWeek ·
- South Korea probes bank breaches amid suspected AI-powered attacks BleepingComputer ·
- ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests The Hacker News ·
- Proposed anti-Flock bills could spell trouble for license plate readers Malwarebytes Labs ·
- Fake brand discounts on social media prey on shoppers’ fear of missing out Help Net Security ·
- tenfold CE: Our free Identity Governance tool just got 2 new features BleepingComputer ·
- IBM security advisory (AV26-997) Canadian Centre for Cyber Security ·
- Alleged dev of Ploutus ATM malware appears in US court after arrest BleepingComputer ·
- Need for Speed: AI-Driven Attacks Are Changing Security Strategies Dark Reading ·
- Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws SecurityWeek ·
- 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms SecurityWeek ·
- RemoveMacAI turns off Apple Intelligence on macOS 27 and deletes its models Help Net Security ·
- The Credential Layer Is Expanding Faster Than Security Teams Can See It The Hacker News ·
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 The Hacker News ·
- Citrix security advisory (AV26-996) Canadian Centre for Cyber Security ·
- Exploitation Hits Rejetto HFS Vulnerability Discovered by AI SecurityWeek ·
- Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity SecurityWeek ·
- Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access The Hacker News ·
- Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) Help Net Security ·
- Detained ShinyHunters hacker reportedly helping FBI track down fellow members Help Net Security ·
CVEs in the news
- CVE-2026-88771 CVSS 9.5 critical · actively exploited Citrix NetScaler Improper Input Validation Vulnerability
- CVE-2026-88772 CVSS 9.5 critical · actively exploited Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- CVE-2026-65660 CVSS 8.8 high · actively exploited Microsoft SharePoint Code Injection Vulnerability
- CVE-2026-76504 CVSS 9.8 critical · actively exploited Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
- CVE-2026-94127 CVSS 9.3 critical · actively exploited F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- CVE-2026-86950 CVSS 8.8 high · actively exploited Apple Multiple Products Out-of-Bounds Write Vulnerability
- CVE-2026-88778 CVSS 8.8 high Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC…
- CVE-2026-35273 CVSS 9.8 critical · actively exploited Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
- CVE-2026-104286 CVSS 9.8 critical · actively exploited Fortinet FortiMail Path Traversal Vulnerability
- CVE-2026-88779 CVSS 8.7 high · actively exploited Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- CVE-2026-87902 CVSS 8.1 high · actively exploited WordPress Core Remote File Inclusion Vulnerability
- CVE-2026-102490 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Improper Privilege Management Vulnerability
Recently exploited
- CVE-2026-88779 CVSS 8.7 high · actively exploited Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- CVE-2026-102489 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Session Fixation Vulnerability
- CVE-2026-102490 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Improper Privilege Management Vulnerability
- CVE-2026-104286 CVSS 9.8 critical · actively exploited Fortinet FortiMail Path Traversal Vulnerability
- CVE-2026-76504 CVSS 9.8 critical · actively exploited Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
- CVE-2026-86950 CVSS 8.8 high · actively exploited Apple Multiple Products Out-of-Bounds Write Vulnerability
- CVE-2026-88771 CVSS 9.5 critical · actively exploited Citrix NetScaler Improper Input Validation Vulnerability
- CVE-2026-88772 CVSS 9.5 critical · actively exploited Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability