Security news.
Today's cybersecurity landscape is marked by urgent patching, active exploitation of critical vulnerabilities, and a persistent focus on supply chain risks, including potential backdoors in widely-sold hardware. Several CISA advisories highlight actively exploited flaws requiring immediate attention from federal agencies and other organizations.
PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut has issued a warning regarding a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software that is currently being exploited in zero-day attacks.
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Vercel has released security patches for two critical vulnerabilities in the Next.js web framework, including CVE-2026-75604, both allowing unauthenticated remote code execution via specially crafted AVIF image files or a path traversal flaw on Windows filesystems.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added CVE-2023-49105 (ownCloud), CVE-2026-53362 (Linux Kernel), and CVE-2026-66384 (JFrog Artifactory) to its KEV Catalog, citing active exploitation and urging federal agencies to patch.
Chinese Routers Sold Worldwide Contain Backdoors
Numerous ZBT routers, sold globally as white-label products, reportedly contain multiple manufacturer-built implants, raising significant supply chain security concerns.
Carhartt data breach exposes information of 12.9 million accounts
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer Carhartt, as confirmed by Have I Been Pwned.
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities have arrested and charged two men accused of being part of the TeamPCP hacking group, linked to a series of developer supply chain attacks.
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
Academic researchers have developed GPUThor, a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that bypasses ECC, allowing denial-of-service and privilege escalation to a root shell.
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Researchers have revealed a vulnerability in Amazon Kiro, an AI-powered IDE, where prompt injection and Kiro Powers could facilitate data exfiltration.