Security news.
Today's security landscape is marked by critical vulnerability exploits and the growing complexity introduced by AI. Several zero-day flaws are under active attack, alongside ongoing sophisticated espionage and financial fraud campaigns by threat groups. Organizations are urged to prioritize patching and bolster defenses against these evolving threats.
Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released emergency patches for "LegacyHive," a Windows zero-day actively exploited to gain SYSTEM access, following its public disclosure post-July Patch Tuesday.
Critical VMware vCenter RCE flaw exploited for reverse SSH access
A critical VMware vCenter Syslog Server vulnerability (CVE-2026-59310) allowing remote code execution is being actively exploited to deploy reverse SSH tools for persistence.
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors are actively exploiting CVE-2026-55040, a critical SharePoint authentication bypass vulnerability, following the release of proof-of-concept code.
Hackers breach govt webmail while running parallel crypto fraud
The Jewelbug hacker group is performing espionage operations against governments and militaries while simultaneously engaging in cryptocurrency fraud, using shared infrastructure.
Trezor discloses data breach affecting nearly 14,000 customers
Hardware wallet manufacturer Trezor reported a data breach impacting nearly 14,000 customers due to a hack at its shipping provider, ShipMonk.
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
An ongoing campaign named "City-Forum" is using custom tools to steal data exposed to anonymous users via Salesforce Experience Cloud and ServiceNow customer portals.
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
A newly disclosed flaw in AI API calls from OpenAI, Anthropic, and Google allowed researchers to recover internal reasoning and secrets like API keys and passwords from session logs.
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Fortinet has released patches for vulnerabilities in FortiWeb and FortiManager that could allow attackers to log in with random credentials or impersonate FortiGate appliances.