Security news.
Today's security landscape is marked by a flurry of critical vulnerabilities and breaches, alongside the increasing sophistication of AI in both defense and offense. Several zero-day exploits have been patched in widely used software and networking devices, while significant data exposures highlight persistent security challenges.
Adobe Patches Magento Zero-Day Under Active Exploitation
Adobe has released urgent patches for a critical (CVSS 10.0) zero-day flaw, CVE-2026-75650, in Adobe Commerce and Magento Open Source, actively exploited to deploy backdoors and web shells.
N-able Patches Critical Zero-Day in N-central
N-able has issued a patch for a critical zero-day vulnerability in its N-central RMM software, advising administrators to check for unauthorized new user accounts.
MikroTik Patches Critical Flaws Chained to Hack Routers
MikroTik has released patches for critical vulnerabilities, dubbed "MikroTrick," that allowed attackers to bypass authentication, overwrite configuration, and take over devices.
FreeIPA Flaw Lets Anonymous Clients Create Administrator Credentials
A critical flaw chain in FreeIPA allows unauthenticated clients to create Kerberos identities and add them to the administrators group, impacting Linux domain security.
Mathspace Data Breach Exposes Over 1 Million People
The online learning platform Mathspace suffered a data breach exposing the information of over 1 million students, teachers, staff, and parents from a compromised Metabase instance.
220 Million Traveler Records Exposed in Vietnam-Linked APIS Leak
An exposed Advance Passenger Information System (APIS) database, linked to Vietnam, leaked 220 million passenger and crew records, including passport and flight details, accessible via default cloud credentials.
Hackers Develop AI Frameworks for Widespread Credential Theft
Threat actors are increasingly using sophisticated multi-agent AI frameworks to automate all stages of attacks, moving beyond simple AI-powered coding assistance for more efficient credential theft.
Microsoft Warns of Windows Server 2025 Application Crashes
Microsoft has alerted users to potential application crashes on Windows Server 2025, attributing them to recent memory management changes.