← Latest brief

Security news.

·Morning Brief

Today's cybersecurity landscape is marked by urgent patch releases for critical vulnerabilities, ongoing exploitation of zero-day flaws, and a significant international takedown of a long-standing botnet. Several vendors, including SonicWall, Rockwell Automation, and browser developers, have released updates to address severe security issues, some of which are actively exploited.

BLEEPINGEXPLOIT
Sep 2READ

SonicWall Warns of Actively Exploited SMA 1000 Zero-Days

SonicWall has released security updates for two critical zero-day vulnerabilities (CVE-2026-83548, CVE-2026-83549) in its Secure Mobile Access (SMA) 1000 series VPN appliances, which are being chained for unauthenticated remote code execution.

SECURITYWEEKMALWARE
Sep 2READ

23-Year-Old Sality P2P Botnet Disrupted in Global Takedown

International law enforcement and private partners successfully dismantled the Sality botnet, active for over two decades, by manipulating its peer list and taking down payload URLs to prevent new infections.

BLEEPINGBREACH
Sep 2READ

Dropbox Accounts Breached via Lenovo Email Verification Flaw

Dropbox is notifying users that unauthorized parties accessed their accounts by exploiting a vulnerability in Lenovo's email verification process to create fraudulent Lenovo IDs.

DARK READINGVULN
Sep 1READ

Attackers Exploiting Critical JFrog Artifactory Flaw

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being actively exploited to gain administrative access shortly after its public disclosure.

SECURITYWEEKBREACH
Sep 2READ

Malicious Virtualizor Update Served via BGP Hijacking

Threat actors used BGP hijacking and a valid TLS certificate to redirect traffic for Virtualizor updates to malicious servers, delivering compromised software.

SECURITYWEEKPATCH
Sep 2READ

Rockwell Automation Patches Over a Dozen Vulnerabilities

Industrial giant Rockwell Automation released advisories for numerous products including RSLinx Classic, ArmorStart, and FactoryTalk, addressing over a dozen security flaws.

SECURITYWEEKEXPLOIT
Sep 2READ

Exploit Published for Fresh Cleo Harmony Vulnerability

A public exploit is now available for a security defect in Cleo Harmony that allows remote attackers to bypass authentication by manipulating argument bearers.

BLEEPING
Sep 2READ

Microsoft Defender Flags Legitimate Google Search Links as Malicious

Microsoft is investigating an issue where Defender for Office 365 is erroneously blocking access to legitimate Google search results, mistakenly identifying them as malicious.

Generated twice daily from public security RSS feeds. Informational only.