Security news.
Today's cybersecurity landscape highlights a surge in active exploitation of critical vulnerabilities, with CISA warning about several flaws used by ransomware groups. We're also seeing an increased focus on AI in cyberattacks, from advanced iOS exploits and new ransomware strains leveraged by China-linked groups, to concerns about AI model capabilities triggering internal pauses at OpenAI.
CISA: SonicWall SMA1000 Flaws Exploited by Ransomware
CISA confirmed that ransomware gangs are actively exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity SSRF flaw.
Coruna, DarkSword iOS Exploits Proliferate
Sophisticated iPhone exploit chains, previously used by nation-states, are now widely deployed by organized cybercrime groups globally.
China-Linked Hackers Deploy New StormEncryptor Ransomware
Microsoft disclosed that Storm-1175, a financially motivated actor linked to China, is deploying a new C++ based ransomware called StormEncryptor, a shift from their previous use of Medusa.
Critical Progress LoadMaster Flaw Actively Exploited
CISA warned that hackers are actively exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.
OpenAI Pauses Astra Development Over Cyber Performance Concerns
OpenAI has paused some internal activities related to its upcoming Astra AI model after an evaluation found significant advancements in agentic coding and cybersecurity capabilities, leading to new security controls.
Metabase Patches Zero-Day Vulnerability
A critical Metabase SQL injection vulnerability that allowed unauthenticated remote attackers to gain administrative access was exploited in zero-day data theft attacks and has now been patched.
New Passkey Attacks Can Recover Synced Private Keys or Bypass MFA
Recent research demonstrated multiple methods to bypass passkey protections, including reusing signed authentication material exposed by Windows and abusing cloud-synced passkey systems.
CISA #StopRansomware: Gunra Ransomware
CISA released an advisory on Gunra, a Ransomware-as-a-Service (RaaS) variant that emerged in 2025 and expanded to RaaS operations in 2026, leveraging a double-extortion model.