Security news.
Today's cybersecurity landscape highlights a surge in active exploitation, with CISA issuing warnings for several flaws and hackers leveraging SQL injection to deploy post-exploitation toolkits. AI-related security concerns continue to grow, ranging from AI agents going rogue during tests to the weaponization of AI in phishing and malware campaigns.
CISA Adds JetBrains TeamCity Deserialization Flaw to KEV Catalog
CISA has added CVE-2026-63077, a deserialization of untrusted data vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities Catalog, urging federal agencies to remediate within three days due to active exploitation.
Hackers Run Khunt Post-Exploitation Toolkit from Oracle Database
Threat actors exploited a SQL injection vulnerability to install and operate the Khunt post-exploitation toolkit directly within an Oracle database, subsequently breaching a corporate network.
CISA Warns of Actively Exploited Langflow, N-central, Apache Tomcat Flaws
CISA has issued an urgent warning to federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow (code injection), N-central (authentication bypass), and Apache Tomcat (sensitive data encryption bypass) within three days.
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation now employs browser fingerprinting across more than 250 domains to selectively display fake software download lures to Mac users, effectively hiding malicious content from crawlers and sandboxes.
Veeam, Terraform MCP, Django Patch Critical Flaws Including CVSS 10.0 Cross-Tenant Bug
Critical vulnerabilities, including an unauthenticated flaw in Veeam Service Provider Console (CVSS 9.5) and a cross-tenant bug in HashiCorp Terraform MCP Server (CVSS 10.0), have been patched by their respective vendors.
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
A memory corruption vulnerability (CVE-2026-64531, CVSS 7.8) dubbed "OVSwrap" in the Linux kernel's Open vSwitch datapath allows local users to achieve root privileges, with public exploits available for many kernel builds.
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Researchers at Palo Alto Networks have demonstrated novel attacks against Google's synced passkey implementation, highlighting methods malware can use to hijack passkey-protected accounts.
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files
A critical vulnerability (CVE-2026-59774, CVSS 9.8) in Gitea versions 1.22.1 through 1.27.0 allowed unauthenticated attackers to read any file accessible by the service account through crafted Org-mode markup in a public repository. The flaw is fixed in Gitea 1.27.1.