Security news.
Today's cybersecurity landscape is marked by widespread exploitation of critical vulnerabilities in popular software like Oracle WebLogic and Zimbra. Threat actors are also actively employing sophisticated phishing campaigns and novel malware techniques, highlighting the persistent need for rapid patching and robust security measures.
CISA Warns of Actively Exploited Oracle WebLogic Vulnerability
CISA has added a maximum-severity flaw, CVE-2026-21962, in Oracle HTTP Server and WebLogic Server to its KEV catalog due to widespread active exploitation, allowing unauthenticated attackers to access critical data.
Hackers Breached Over 270 Zimbra Servers in Ongoing Attacks
Threat actors have compromised over 270 Zimbra instances by exploiting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability, CVE-2026-73570, which CISA has ordered federal agencies to patch urgently.
Mirage2FA Phishing Campaign Hits 4,500 US and EU Companies
The Mirage2FA phishing-as-a-service toolkit is abusing Microsoft 365 login flows to bypass two-factor authentication, potentially compromising 48% of targeted email addresses, primarily in the US.
Attackers Target miniOrange SAML Flaws for WordPress Admin Access
Bad actors are actively attempting to exploit two severe unauthenticated authentication bypasses (CVE-2026-61979 and CVE-2026-61980) in the miniOrange SAML 2.0 Single Sign On plugin, allowing login as any WordPress user, including administrators.
First Malware Built Specifically for Car Head Units Fuels Botnet
Kaspersky researchers have identified the first malware specifically designed for car head units, linking it to the BadBox botnet which has compromised millions of devices.
E4del and PINHOLE RATs Use FTP Banners as Dead Drops for Malware Commands
A new campaign is employing FTP banners as dead drop resolvers to deliver two previously unreported remote access trojans, E4del and PINHOLE, showcasing a novel method for command-and-control infrastructure.
WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
WhatsApp is enhancing its account security by introducing support for multiple passkeys and stronger two-step verification, aiming to provide users with more robust protection against unauthorized access.
Police Arrest Dozens of Suspects in Global Cybercrime Crackdown
Law enforcement agencies from 22 countries collaborated to identify 263 suspects and arrest 58 individuals linked to cybercrime networks coordinated by African crime groups.