Microsoft Working To Patch 'RoguePlanet' Zero-Day
(slashdot.org)
1.
2.
CISA orders feds to patch max severity Joomla plugin flaw by Friday
(bleepingcomputer.com)
3.
Critical Fortinet FortiSandbox flaws now exploited in attacks
(bleepingcomputer.com)
4.
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
(bleepingcomputer.com)
6.
7.
Cisco warns of critical Unified CM flaw with PoC exploit code
(bleepingcomputer.com)
8.
Acer working to patch max severity zero-days in Wave 7 routers
(bleepingcomputer.com)
9.
Critical Kirki flaw exploited to hijack WordPress admin accounts
(bleepingcomputer.com)
10.
11.
WP Maps Pro bug exploited to create admin accounts on WordPress sites
(bleepingcomputer.com)
12.
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
(bleepingcomputer.com)
13.
Microsoft 0-day feud escalates as researcher threatens another exploit dump
(news.ycombinator.com)
14.
Hackers exploit FortiClient EMS flaw to push infostealer malware
(bleepingcomputer.com)
15.
CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
(bleepingcomputer.com)
16.
17.
KnowledgeDeliver flaw exploited as a zero-day to install web shells
(bleepingcomputer.com)
18.
BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass
(news.ycombinator.com)
19.
CISA orders feds to patch actively exploited Drupal vulnerability
(bleepingcomputer.com)
20.
CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude
(news.ycombinator.com)
21.
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
(bleepingcomputer.com)
22.
Trend Micro warns of Apex One zero-day exploited in the wild
(bleepingcomputer.com)
23.
Drupal: Critical SQL injection flaw now targeted in attacks
(bleepingcomputer.com)
24.
Max severity Cisco Secure Workload flaw gives Site Admin privileges
(bleepingcomputer.com)
25.
Microsoft warns of new Defender zero-days exploited in attacks
(bleepingcomputer.com)
26.
Max-severity flaw in ChromaDB for AI apps allows server hijacking
(bleepingcomputer.com)
27.
Microsoft Exchange Zero-Day Under Attack, No Patch Available
(darkreading.com)
28.
Exploit available for new DirtyDecrypt Linux root escalation flaw
(bleepingcomputer.com)
29.
30.
Avada Builder WordPress plugin flaws allow site credential theft
(bleepingcomputer.com)