Security news.
Today's security landscape is dominated by critical infrastructure vulnerabilities and the increasing use of AI in both defense and offense. Multiple high-severity flaws in network devices and industrial control systems require immediate patching, while threat actors are leveraging AI to accelerate attacks and evade detection.
Critical Cisco Nexus 9000 Flaw Allows Remote Code Execution
Cisco has patched a critical vulnerability (CVE-2026-20212, CVSS 9.8) in 10 Silicon One-based Nexus 9000 switches, allowing unauthenticated remote attackers to execute code as root.
HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw
Hewlett Packard Enterprise (HPE) has released a patch for a critical vulnerability in ArubaOS-CX, their network operating system, which could lead to remote code execution.
Manchester Airports Group Data on 8.8 Million People Leaked
After reportedly refusing a ransom demand, the Manchester Airports Group saw approximately 550GB of data, affecting 8.8 million individuals, published by a hacker group claiming access via exposed admin keys.
BraZetsu Malware Transforms Windows Hosts into Criminal Marketplace Inventory
A sophisticated Python-based Windows malware framework, BraZetsu, is being used to convert compromised systems into valuable commercial inventory for Initial Access Brokers (IABs) on an underground marketplace.
ASCII Smuggling Leveraged for Phishing Evasion
Invisible Unicode characters, previously used for AI prompt injection, are now being employed by attackers to obfuscate words in phishing emails, bypassing traditional email filters.
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
A high-severity SQL injection flaw (CVE-2026-19949) in a popular WordPress migration plugin could allow unauthenticated attackers to achieve remote code execution on over 3 million sites.
Attackers Use Node.js Runtime as Malware Delivery Tool
Threat actors are exploiting the trusted Node.js JavaScript runtime to deploy malicious payloads in targeted attacks against government, tech companies, and hotels since February 2026.
Critical Elementor Pro Flaw Exploited to Take Over WordPress Sites
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being actively exploited to deliver webshells and execute arbitrary commands.