Security news.
Today's security landscape is marked by a surge in AI-related security concerns, from new funding for AI runtime security startups to attackers actively exploiting AI tools and platforms. Alongside this, significant vulnerabilities in popular software and a massive data breach involving driver's license images highlight the ongoing need for vigilant patching and robust identity verification.
CISA Adds Seven Exploited Flaws to KEV Catalog
CISA has added seven vulnerabilities, including a critical SonicWall SMA 1000 SSRF (CVE-2026-83548) and a Sangoma Switchvox SQL injection (CVE-2026-9586), to its Known Exploited Vulnerabilities catalog.
153 Million Driver License Images Offered on Dark Web
Digital scans of US and Canadian driver’s licenses, likely stolen from identity verification company IDScan.net, are being sold on the dark web, prompting an FBI investigation.
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
A high-severity SQL injection flaw (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to achieve remote code execution on affected WordPress sites.
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool
Threat actors are actively leveraging the Node.js JavaScript runtime to deploy malicious payloads in targeted attacks against government, technology, and hotel sectors since February 2026.
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Brazil's most sophisticated threat group is exploiting vulnerabilities in the country's financial systems to directly steal funds.
Pegasus Zero-Click Spyware Infects Serbian Student Movement Member's iPhone
NSO Group's Pegasus spyware was found on an iPhone belonging to a Serbian student protest movement member, infected via an iMessage zero-click exploit.
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Cisco has warned of publicly disclosed S/MIME flaws that could expose encrypted email content and released patches for critical IOS XR and Nexus bugs enabling remote code execution and authentication bypass.
Plex Warns Users to Patch Security Vulnerabilities Immediately
Plex has urged users to immediately update their desktop clients and media servers to patch multiple undisclosed security vulnerabilities.