Security news.
Today's security landscape is heavily influenced by actively exploited vulnerabilities and the increasing use of AI in cyberattacks. Organizations are urged to patch critical flaws promptly, as threat actors, including ransomware groups and state-sponsored entities, are quickly leveraging known weaknesses.
IDScan Confirms Breach of 153 Million Driver's Licenses
Identity verification company IDScan confirmed a data breach affecting customer data in its cloud, following reports of a massive database containing over 153 million driver's license scans being offered for sale.
Cisco FMC Flaws Exploited by Ransomware and State-Sponsored Hackers
Cisco Talos reported that two recently patched Secure Firewall Management Center (FMC) vulnerabilities (CVE-2026-20079) are being actively exploited by three distinct threat clusters, including ransomware gangs and state-sponsored attackers.
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Federal Patch Deadline
CISA added critical vulnerabilities affecting Cisco (CVE-2026-20079), Citrix (CVE-2026-19490), and Fortinet (CVE-2025-25249) to its KEV catalog, mandating federal agencies patch by September 12, 2026, due to active exploitation.
AI-Powered Attack Exploits PaperCut Flaws, Hacks 395 Organizations
A suspected Russian-speaking threat actor utilized hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers, compromising hundreds of organizations.
New 'BlueMoon' Kit Exploited Windows and Chrome Zero-Day Flaws
Multiple cyber-espionage groups deployed a sophisticated exploit kit named "BlueMoon," leveraging zero-day vulnerabilities in Microsoft Windows and Google Chrome for targeted attacks.
New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
A researcher published another zero-day exploit for Windows Defender, dubbed "ShieldCrash," which provides full System privileges on Windows machines, even those running the latest September 2026 patches.
Surfshark VPN Discloses Breach of Internal Testing, Proxy Servers
Surfshark announced that hackers gained unauthorized access to one of its internal test servers due to a misconfiguration that exposed it to the internet.
Microsoft Plugs Nearly 1,000 Security Holes in Record Patch Tuesday
Microsoft released updates to address an unprecedented 974 security vulnerabilities in Windows and other software, with two flaws actively exploited and 58 more identified as likely to be exploited.