Topic
APT / Nation-State.
24 stories of advisories, analysis, and defensive guidance in this topic.
Laundry Bear exploits Exchange OWA zero-day to deploy persistent OWAReaper backdoor via email
The Russian state-sponsored group Laundry Bear (TA488) is using a "half-click" exploit against Microsoft Exchange Outlook Web Access (OWA) to deploy the OWAReaper backdoor.
Russian Hackers Maintain Mailbox Access After Credential Rotation via Microsoft OWA Flaw
馃毃 Russian-linked actors are targeting Microsoft Exchange Online environments through vulnerabilities in Outlook Web Access (OWA).
Unauthenticated attackers exploit hard-coded credentials in Cisco Secure Firewall Management Center
Attackers are actively exploiting a hard-coded, low-privilege credential flaw in Cisco Secure Firewall Management Center (FMC) software.
Unauthenticated attackers exploit command injection flaws in Arista VeloCloud and Fortinet FortiOS
Critical vulnerabilities in Arista VeloCloud Orchestrator and Fortinet FortiOS are currently being exploited in the wild.
Russian state-sponsored actors target Zimbra Collaboration Suite users through phishing campaigns
New intelligence indicates that Iranian-affiliated cyber actors have been targeting Programmable Logic Controllers (PLCs) used throughout US critical infrastructure.
Zero-day vulnerability chain enables root access and malware deployment on SonicWall SMA1000 appliances
Threat actors have been exploiting a chain of two zero-day vulnerabilities in SonicWall SMA1000 appliances for weeks.
Attackers exploit SonicWall SMA zero-day vulnerabilities to gain unauthorized root access
馃毃 Attackers are actively exploiting zero-day vulnerabilities within SonicWall Secure Mobile Access (SMA) appliances.
Zero-day vulnerability chain enables root access and persistence on Siemens ROX II switches
A chain of three zero-day vulnerabilities in Siemens ROX II industrial switches allows attackers to escalate privileges and gain persistent root access.
Crafted CIP packets trigger denial-of-service and halt industrial I/O on Rockwell Flex 5000 adapters
Sending crafted CIP packets to a FLEX 5000 EtherNet/IP adapter can trigger a denial-of-service state that halts industrial I/O. Recovery requires a physical power cycle of the module.
Unauthenticated attackers exploit zero-day vulnerabilities in SonicWall SMA1000 appliances for code execution
Threat actors are actively exploiting two zero-day vulnerabilities in SonicWall SMA1000 appliances to perform server-side request forgery and arbitrary code execution.
Attackers can execute remote commands on Cisco 871 routers via CSRF flaw
Cisco has a critical cross-site request forgery (CSRF) flaw in the HTTP Administration component of its IOS software.
Attackers exploit Joomla extension vulnerabilities to execute remote code via malicious file uploads
Two critical vulnerabilities in popular Joomla extensions-Balbooa Forms and iCagenda-are being actively exploited in the wild to achieve unauthenticated remote code execution.
Unauthenticated attackers can execute remote code via NGINX rewrite module vulnerabilities
A critical flaw in the `ngx_http_rewrite_module` can lead to worker process restarts or remote code execution.
Japanese teenager detained following disruptive cyberattack on anime streaming platform
Tokyo police have arrested a high school student suspected of disrupting the Bandad Channel anime streaming service through large-scale unauthorized cancellations.
Remote Code Execution Vulnerability in Microsoft SharePoint Under Active Exploitation by Attackers
Attackers are actively exploiting a high-severity deserialization vulnerability in Microsoft SharePoint.
Critical RCE Flaw in Langflow AI Enables Full Server Compromise and Data Theft
Langflow AI's tool for building AI-powered agents has been exploited for unauthenticated remote code execution (RCE) due to a critical vulnerability in versions prior to 1.9.0.
Critical Authentication Bypass in SimpleHelp Enables Malware Deployment: Immediate Patch Urged
A critical authentication bypass vulnerability in SimpleHelp (CVE-2026-48558) has been actively exploited by threat actors to deploy new malware.
Over 100,000 WordPress Sites at Risk from Unauthenticated Info Disclosure in Gravity SMTP Plugin
Hackers are actively exploiting an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin, affecting over 100,000 sites.
Critical Joomla Content Editor Flaw Actively Exploited: Immediate Patch Urged by CISA
A critical vulnerability in the Joomla Content Editor (JCE) extension has been actively exploited, allowing attackers to upload and execute PHP code.
CISA Catalogs Two Actively Exploited Vulnerabilities: Critical Patches Urged
Two critical vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog: Cisco Catalyst SD-WAN Manager (CVE-2026-20262) and LiteSpeed cPanel Plugin (CVE-2026-54420).
Microsoft Fixes Critical XSS Flaw in Exchange Server Actively Exploited by Threat Actors
Microsoft has patched an actively exploited vulnerability in Exchange Server that allows threat actors to execute arbitrary JavaScript code via cross-site scripting (XSS) attacks.
Microsoft's June Patch Tuesday Unveils 206 Fixes: Urgent Patch Needed for Self-Spreading Vulnerability
Microsoft's June Patch Tuesday delivered an unprecedented 206 security fixes, with AI playing a significant role in vulnerability discovery.
Unauthorized Access via ServiceNow Vulnerability Highlights Need for AI-Driven Security Measures
A newly identified vulnerability in ServiceNow has been exploited by attackers to gain unauthorized access.
Gamaredon Exploits WinRAR Zero-Day: Urgent Patch Needed for Windows Users
The WinRAR vulnerability (CVE-2025-8088) has been actively exploited by Gamaredon to execute arbitrary code through malicious archive files, posing a significant threat to systems using the Windows ve