Security news.
Today's security landscape is dominated by multiple critical vulnerabilities under active exploitation, prompting urgent CISA advisories. Ransomware groups continue to evolve tactics, with CL0p naming new victims from their PTC Windchill campaign and a global operation using thousands of hacked WordPress sites to spread malware. Meanwhile, the US has charged 17 Iranian hackers targeting universities and organizations worldwide.
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA has added four critical vulnerabilities, including CVE-2026-65400 (macOS), CVE-2026-55040 (SharePoint), CVE-2026-59310 (vCenter), and CVE-2026-33824 (Microsoft IKE), to its KEV catalog due to active exploitation.
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The Cl0p ransomware gang has listed major companies like Shell, Philips, and Fiserv among over 40 victims of their campaign exploiting vulnerabilities in PTC Windchill and FlexPLM servers.
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware
A global cybercrime operation is abusing almost 2,000 compromised WordPress websites as infrastructure to distribute malware, commandeer hosts, and store stolen data.
US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
The US has indicted 17 members of the Mabna Institute for targeting hundreds of universities and organizations in the US and abroad, offering significant rewards for information on five key individuals.
Oracle's August 2026 Security Update Patches 943 Vulnerabilities
Oracle has released its quarterly security update, addressing 943 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs.
CareCloud Data Breach Impact Grows to 3.7 Million Individuals
The data breach affecting healthcare technology provider CareCloud has been confirmed to impact approximately 3.7 million individuals, significantly higher than initially estimated.
Microsoft Fixes Known Issue Causing Windows Defender Crashes
Microsoft has released a fix for a bug that caused Windows Defender to crash with 0xc0000005 access violation errors on some systems following a recent security update.