Security news.
Today's cybersecurity landscape is marked by widespread exploitation, with critical vulnerabilities in VMware, Cisco, and WordPress plugins actively targeted by ransomware and other threat actors. Multiple data breaches affecting utilities and government agencies highlight the persistent risk of credential theft and system compromise. Additionally, new multi-platform malware campaigns leverage novel communication channels, emphasizing the need for robust, continuous monitoring and swift patching.
Cisco Secure Email Gateway Zero-Day Actively Exploited
Cisco has warned of active exploitation of CVE-2026-76461, a critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway, allowing unauthenticated remote root command execution. CISA has added this flaw to its Known Exploited Vulnerabilities Catalog.
Ransomware Gangs Exploiting Critical VMware RCE Flaw
CISA has issued a warning that ransomware groups are now actively exploiting a critical VMware vCenter remote code execution vulnerability, patched in July, alongside ongoing attacks.
China-Linked Hackers Deploy GRIMWEDGE via Chrome-Windows Zero-Day Chain
A Chinese threat actor exploited recently patched Google Chrome and Microsoft Windows zero-day vulnerabilities in a spear-phishing campaign to deliver the GRIMWEDGE JavaScript backdoor, targeting NGOs.
WordPress Sites Targeted via WooCommerce Plugin Vulnerability
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress, enabling the upload of PHP backdoors.
CenterPoint Energy Confirms Data Breach After Leak
CenterPoint Energy disclosed a breach of customer personal information after an attacker leaked data allegedly stolen from the utility company, with claims of 7.5 million records compromised.
KREMLIN Banking Malware Hijacks Chrome and Edge Browsers
An undocumented Brazilian banking malware, KREMLIN, is hijacking Chrome and Edge browsers with malicious extensions to steal credentials and session tokens from at least a dozen Brazilian banks.
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents
Cybersecurity agencies report that Iran's intelligence service is deploying Windows malware, controlled via Telegram, to spy on dissidents, journalists, and activists globally, capable of stealing messages and recording audio.
BambooToken Malware Controls Windows and Linux via MQTT Protocol
A new multi-platform malware family, BambooToken, has been identified using the Message Queueing Telemetry Transport (MQTT) protocol for command and control of Windows and Linux systems in attacks across Asia and South America.