Security news.
Today's cybersecurity landscape is marked by widespread exploitation of critical vulnerabilities in popular software and infrastructure, with several high-impact flaws seeing active in-the-wild attacks shortly after disclosure. The rise of AI continues to influence both offensive and defensive strategies, as threat actors leverage AI for exploit porting and data exfiltration, while some deploy deceptive tactics to evade AI-assisted analysis.
Thousands of Microsoft Exchange Servers Vulnerable to Hijack Attacks
Approximately 22,000 Microsoft Exchange servers remain unpatched against a high-severity authentication bypass vulnerability, enabling attackers to hijack all user mailboxes.
Hackers Actively Exploiting Critical Langflow Vulnerability
A critical Langflow vulnerability, CVE-2026-0768, allowing unauthenticated attackers to execute arbitrary Python code remotely, is now being exploited in the wild.
Critical JFrog Artifactory Vulnerability Exploited
An authentication bypass vulnerability, CVE-2026-82329, in JFrog Artifactory is reportedly being exploited just days after its public disclosure.
PaperCut Zero-Days Exploited for Data Theft
Recently patched zero-day vulnerabilities (CVE-2026-82078 and CVE-2026-81578) in PaperCut NG and MF print management software are now being actively abused for data theft attacks. CISA has added them to its KEV catalog.
WatchGuard Patches Critical Remote Code Execution Vulnerabilities
WatchGuard has released patches for three critical vulnerabilities in Fireware OS that could allow unauthenticated attackers to execute arbitrary code remotely.
Attackers Steal METR AI API Key, Consume $600,000 in Credits
METR, an AI research non-profit, disclosed two security incidents where external actors stole an API key and consumed approximately $600,000 worth of AI credits.
Russia-Aligned UAC-0099 Uses "GuardBreaker" to Disrupt AI Analysis
The Russia-aligned threat actor UAC-0099 is employing a new technique dubbed "GuardBreaker" to plant disruptive prompts in malware, aiming to interfere with AI-assisted analysis by tripping large language model safety mechanisms.
Aesto Health Data Breach Impacts 9.5 Million
Hackers stole personal and health information belonging to 9.5 million individuals from healthcare technology company Aesto Health's AWS infrastructure.