Security news.
Today's security landscape is dominated by a wave of critical patches and actively exploited vulnerabilities, particularly impacting Microsoft, Adobe, and VMware products. Several zero-day exploits are being leveraged in the wild, underscoring the urgency for immediate patching and heightened vigilance against sophisticated threat actors.
New Microsoft Defender 'ShieldBreak' Zero-Day Grants SYSTEM Privileges
A new Microsoft Defender zero-day exploit, "ShieldBreak," has been released, demonstrating a patch bypass for CVE-2026-50656 (RoguePlanet) and granting SYSTEM privileges.
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
A newly disclosed Windows zero-day vulnerability (CVE-2026-68820) in the afd.sys kernel-mode driver, capable of privilege escalation, is being actively exploited by North Korean threat actors.
Attackers Exploit VMware vCenter Vulnerability for Persistent Remote Access
Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter, to achieve arbitrary code execution and persistent remote access.
Hackers Leverage New Microsoft SharePoint Exploit in Attacks
A proof-of-concept exploit for a critical Microsoft SharePoint vulnerability has been published by Rapid7, and hackers have already begun using it in active attacks.
Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
Cisco has released patches for CVE-2026-20349, a high-severity denial-of-service vulnerability in Secure Firewall ASA and FTD software, which is being actively exploited to crash devices.
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe has issued critical updates addressing multiple severe vulnerabilities, including three with a CVSS score of 10.0, in ColdFusion, Commerce, and Campaign Classic that could lead to arbitrary code execution.
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
The LiteLLM library was compromised via the Trivy hack, leading to the distribution of information-stealing malware to its users and potentially exposing over 2,500 organizations to credential theft.
DeadLock Ransomware Uses Blockchain to Resist Infrastructure Takedown
The DeadLock ransomware operation is employing a decentralized, blockchain-backed infrastructure for victim communication and data-leak activities, enhancing its resilience against takedowns.