Threat actors have been exploiting three high-severity vulnerabilities in JFrog Artifactory to compromise deployments and install backdoors, cybersecurity firm Wiz reports. Many organizations use Artifactory to manage software artifacts, binaries, AI models, containers, and packages. The three flaws, CVE-2026-42016, CVE-2026-42018,… Read More "Three JFrog Artifactory Flaws Exploited for Backdoor Deployment"
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
A critical-severity vulnerability in Sogou Input Method has been exploited by a Chinese threat actor to deploy a backdoor, Gen Threat Labs reports. Developed by Tencent, Sogou Input Method is one of the most popular Chinese-language input method editors (IMEs)… Read More "Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution"
ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks. Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization… Read More "ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks"
PaperCut Flaws Exploited in AI-Powered Attacks
Two recent PaperCut NG/MF vulnerabilities have been exploited in AI-powered attacks that hit hundreds of organizations worldwide, GreyNoise reports. Tracked as CVE-2026-82078 and CVE-2026-81578, the security defects were disclosed on August 27 as zero-days and patched the next day. They… Read More "PaperCut Flaws Exploited in AI-Powered Attacks"
Check Point Patches Critical VPN Vulnerabilities
Cybersecurity firm Check Point this week announced patches for two critical-severity vulnerabilities in its gateway and firewall products using VPN functionality. Tracked as CVE-2026-85102 and CVE-2026-85103 (CVSS score of 9.8), both security defects could be exploited without authentication for remote… Read More "Check Point Patches Critical VPN Vulnerabilities"
GitLab Vulnerability Exploited One Day After Disclosure
Threat actors have started exploiting a newly patched vulnerability in GitLab one day after public disclosure, attack surface management firm WatchTowr warns. Tracked as CVE-2026-85706 (CVSS score of 10/10), the security defect is described as a path traversal issue that… Read More "GitLab Vulnerability Exploited One Day After Disclosure"
Critical NetScaler Vulnerability Exploited in Attacks
The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks. Tracked as CVE-2026-19490 (CVSS score of 9.3), the security defect impacts all NetScaler ADC and NetScaler Gateway… Read More "Critical NetScaler Vulnerability Exploited in Attacks"
Organizations Warned of Cisco Secure FMC Exploitation
Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year. The security hole, tracked as CVE-2026-20079, is a critical authentication bypass issue that a remote, unauthenticated… Read More "Organizations Warned of Cisco Secure FMC Exploitation"
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports. Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug… Read More "Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks"
Android’s September 2026 Updates Patch 180 Vulnerabilities
After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security updates. As usual, the updates are split into two parts. The… Read More "Android’s September 2026 Updates Patch 180 Vulnerabilities"