Security news.
Today's cybersecurity landscape is marked by critical vulnerabilities across major platforms and ongoing threats to critical infrastructure. Adobe and Ruby on Rails released patches for severe flaws, while CISA issued urgent warnings regarding attacks on water utilities. Supply chain attacks continue to pose significant risks, with an ad firm's script compromised to steal cryptocurrency.
Adobe Campaign Classic Patches Critical RCE Flaw (CVSS 10.0)
Adobe has released security updates to address CVE-2026-48449, a maximum-severity incorrect authorization flaw in Campaign Classic that could allow unauthenticated arbitrary code execution.
Ruby on Rails Patches Critical File Read and RCE Vulnerability
A critical vulnerability in Ruby on Rails has been patched, which could be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution.
Adform Script Compromised to Swap Crypto Wallet Addresses
Attackers modified a JavaScript file from advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses on customer websites.
Amgen Discloses Cloud Data Breach Exposing Patient Health and Proprietary Info
Pharmaceutical company Amgen reported a data breach where threat actors stole corporate and patient information from multiple cloud systems operated by third-party service providers.
Forgotten UEFI Shims Undermining Secure Boot
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities.
CISA Warns of Increased Attacks Disrupting US Water Utilities
CISA is observing a significant increase in cyber threat actors targeting internet-exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector, urging immediate removal of publicly exposed OT.
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Microsoft reported that hijacked hotel Wi-Fi is being used to deliver CornFlake, a remote access trojan (RAT) capable of capturing webcam images, audio, and keystrokes, attributed to a Midnight Blizzard sub-cluster.
Arch Linux Disables AUR Package Adoption Amid Malware Flood
The Arch Linux project has temporarily disabled the adoption of Arch User Repository (AUR) packages following a surge in malicious takeovers of existing packages.