Security news.
Today's security landscape is heavily influenced by the escalating use of AI by threat actors, from generating hyper-personalized phishing emails to automating malware development and exploitation. Critical vulnerabilities in widely used software like GitLab and JFrog Artifactory are under active exploitation, highlighting the need for rapid patching and robust defense strategies as CISA adds more flaws to its KEV catalog.
GitLab Critical RCE Actively Exploited
A maximum-severity path traversal flaw (CVE-2026-85706) in GitLab's repository commits API is being actively probed and exploited, allowing unauthenticated users to read arbitrary files from affected servers.
CISA Adds JFrog Artifactory, ScreenConnect Flaws to KEV Catalog
CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, including two in JFrog Artifactory (CVE-2026-42016, CVE-2026-42018) and one in ConnectWise ScreenConnect (CVE-2026-84869).
JFrog Artifactory Flaws Chained to Deploy Backdoors
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain admin privileges, and install Rust backdoor malware on self-hosted servers.
Cisco FMC Flaws Exploited by Ransomware and State Actors
Cisco reports that three distinct threat clusters, including ransomware gangs and state-sponsored groups, are exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities, including a critical authentication bypass (CVE-2026-20079).
Passkey-Themed Phishing Leads to Microsoft 365 Data Theft
Threat actors linked to groups like ShinyHunters are using social engineering attacks with passkey and single sign-on themes to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.
PaperCut Flaws Exploited in AI-Powered Attacks
A Russian threat actor has leveraged AI to develop, test, and deploy exploits against PaperCut vulnerabilities in hundreds of organizations globally, leading PaperCut to release new security maintenance releases.
Florida DMV Database Breached via Stolen Police Account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach of its DAVID driver database, where attackers gained access using credentials stolen from a police department employee.
Trezor Reports 347,000 Users Targeted in Phishing After Brevo Hack
Hardware wallet provider Trezor announced that 347,000 users were targeted in phishing attacks, with 2,500 clicking malicious links, following the compromise of its marketing platform, Brevo.