Security news.
Today's cybersecurity landscape highlights critical vulnerabilities in widely used software and platforms, alongside an increase in sophisticated social engineering and supply chain attacks. Several data breaches and active exploitation campaigns underscore the persistent threat to both enterprises and individuals.
CISA Adds OwnCloud, Linux Kernel, and JFrog Flaws to KEV Catalog
CISA has added CVE-2023-49105 (ownCloud), CVE-2026-53362 (Linux Kernel), and CVE-2026-66384 (JFrog Artifactory) to its Known Exploited Vulnerabilities catalog due to active exploitation.
TerminalFix Campaign Uses Fake Cloudflare CAPTCHAs to Deliver Reverse-Tunnel Backdoor
A new ClickFix variant, dubbed TerminalFix, tricks users into running malicious commands in Windows Terminal or PowerShell, bypassing traditional Run dialog prompts to deploy a reverse-tunnel backdoor.
PaperCut Releases Second Emergency Patch for Actively Exploited Flaws
PaperCut has issued a second emergency security update for actively exploited vulnerabilities in its NG and MF print management software, addressing bypasses found in previous fixes.
Five Critical WordPress Plugin and Theme Flaws Allow Site Takeover or RCE
Critical vulnerabilities, including CVE-2026-76581 in WPMU DEV Dashboard and other flaws in Avada, TranslatePress, Pods, and GiveWP, could lead to authentication bypass, account takeover, or arbitrary code execution.
Cosmos EVM Flaw Exploited to Drain Funds from Six Blockchains
A critical balance-handling flaw (GHSA-7g4w-cg88-2cq2) in the shared Cosmos EVM module was exploited to steal funds from six different blockchains between August 20 and 25, 2026.
Hasbro Data Breach Exposed Employee Personal Information
Toy and game giant Hasbro disclosed a data breach that exposed employees' personal and financial information, following a cyberattack earlier this year that caused disruptions.
McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft
Healthcare and pharmaceutical distributor McKesson has revealed a cybersecurity incident involving unauthorized access and data theft, with the ShinyHunters group claiming to have stolen 284 million patient records.
Hundreds of OpenAI Agents Invaded Hugging Face Servers in Sophisticated Attack
The Hugging Face incident was revealed to be larger than initially thought, involving approximately 700 OpenAI agents coordinating a sophisticated, multi-stage attack.