Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

2+ day, 13+ min ago   (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...

SecurityWeek
securityweek.com > critical-netscaler-vulnerability-exploited-in-attacks

Critical NetScaler Vulnerability Exploited in Attacks

2+ day, 23+ hour ago   (460+ words) Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks....

SecurityWeek
securityweek.com > organizations-warned-of-cisco-secure-fmc-exploitation

Organizations Warned of Cisco Secure FMC Exploitation

3+ day, 1+ hour ago   (578+ words) Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year. The security hole,…...

SecurityWeek
securityweek.com > mikrotik-patches-critical-flaws-chained-to-hack-routers

MikroTik Patches Critical Flaws Chained to Hack Routers

5+ day, 5+ min ago   (570+ words) Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two…...

SecurityWeek
securityweek.com > elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

1+ week, 22+ hour ago   (589+ words) Hackers have been exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant warns. A highly popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installations. Elementor Pro is…...

SecurityWeek
securityweek.com > vmware-workstation-and-fusion-updates-patch-critical-vulnerability

VMware Workstation and Fusion Updates Patch Critical Vulnerability

1+ week, 1+ day ago   (440+ words) The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. Broadcom on Thursday announced patches for two critical and high-severity vulnerabilities in VMware Workstation and Fusion. The first issue, tracked as…...

SecurityWeek
securityweek.com > exploit-published-for-fresh-cleo-harmony-vulnerability

Exploit Published for Fresh Cleo Harmony Vulnerability

1+ week, 3+ day ago   (441+ words) Organizations are advised to immediately patch a fresh authentication bypass vulnerability affecting the file transfer application Cleo Harmony. Tracked as CVE-2026-84115, the security defect impacts the JWT refresh token logic and allows remote attackers to elevate their privileges via argument…...

SecurityWeek
securityweek.com > sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

1+ week, 4+ day ago   (445+ words) SonicWall is urging customers of its SMA1000 series secure remote access gateway and SSL-VPN appliance platform to patch two new zero-day vulnerabilities that have been exploited in the wild. According to an advisory published by SonicWall on Tuesday, the vulnerabilities and…...

SecurityWeek
securityweek.com > hackers-start-exploiting-critical-langflow-vulnerability

Hackers Start Exploiting Critical Langflow Vulnerability

1+ week, 4+ day ago   (400+ words) Tracked as CVE-2026-0768 (CVSS score of 9.8), the security defect exists within the code validator in Langflow’s custom component editor. Because a user-supplied string is not properly validated before it is used for Python code execution, an attacker could exploit the…...

SecurityWeek
securityweek.com > critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

1+ week, 5+ day ago   (496+ words) A critical vulnerability in JFrog Artifactory is reportedly being exploited in the wild just days after its public disclosure. JFrog Artifactory is a widely used solution for managing the full lifecycle of software artifacts, binaries, AI models, containers, and packages....