Security news.
Today's security landscape is marked by critical patching advisories across multiple vendors and a concerning increase in AI-assisted attacks. Several platforms and services have reported breaches leading to data exposure and phishing campaigns, underscoring the ongoing need for vigilance and timely updates.
GitLab Urges Immediate Patch for Max Severity Path Traversal Flaw
GitLab has called for immediate patching of a maximum-severity path traversal vulnerability, CVE-2026-85706, highlighting the critical risk it poses to servers.
Check Point Patches Critical VPN Vulnerabilities
Check Point has released patches for critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could lead to remote code execution.
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Cisco reports that multiple threat clusters, including ransomware groups and state-sponsored actors, are actively exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities, including a critical authentication bypass (CVE-2026-20079).
Trezor and Other Crypto Wallets Targeted in Brevo Phishing Attack
A breach of the Brevo marketing platform led to phishing emails being sent to 347,000 users of Trezor, BitBox, and CoinTracking, with 2,500 Trezor users reportedly clicking malicious links.
PaperCut Flaws Exploited in AI-Powered Attacks Against Hundreds of Organizations
A Russian threat actor utilized AI to develop and deploy exploits against vulnerable PaperCut NG/MF servers, compromising hundreds of organizations globally.
Anthropic Reports Russian Hackers Used Claude AI for Malware Evasion
Anthropic revealed that criminal groups, including Russian hackers, are increasingly targeting AI vendor infrastructure to automate malware evasion and steal pre-release AI models.
Attackers Chain JFrog Artifactory Flaws for Admin Control and Backdoors
Cloud security company Wiz observed attackers chaining two previously fixed JFrog Artifactory vulnerabilities to gain administrator control and plant backdoors on unpatched self-hosted servers.
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Oleksii Oleksiyovych Lytvynenko, a developer for the Conti ransomware group, has been sentenced to four years in prison in the U.S. following his arrest in Ireland in 2023.