Security news.
Today's cybersecurity landscape is marked by widespread active exploitation of critical vulnerabilities, including Google Pixel modem flaws and multiple WordPress plugin weaknesses. Agencies have also exposed Iranian surveillance malware, while large-scale breaches and significant patch releases from major vendors underscore the persistent threat environment.
Critical ScreenConnect Flaw Actively Exploited
CISA has confirmed active exploitation of a critical ConnectWise ScreenConnect vulnerability, urging immediate patching.
Google Patches Actively Exploited Pixel Modem Flaw
Google has issued patches for a high-severity privilege escalation flaw (CVE-2026-58704) in its Pixel Cellular Modem, which has been under limited targeted exploitation.
Acronis cPanel Backup Plugin Vulnerability Exploited
Acronis warns that a high-severity local privilege escalation flaw (CVE-2026-87886) in its Backup plugin for cPanel and WHM has been actively exploited.
WSO2 API Manager Flaw Exploited with Forged Admin Tokens
A critical JWT bypass vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited to forge admin tokens and achieve account takeover.
Unauthenticated RCE Flaws Affect 200,000+ WordPress Sites
Vulnerabilities in The Events Calendar plugin could expose over 200,000 WordPress sites to unauthenticated remote code execution.
WooCommerce Wholesale Lead Capture Flaw Exploited
Threat actors are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin to upload PHP web shells and achieve RCE.
US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Malware
Government agencies have detailed "Chosen Brick," a Windows surveillance malware controlled via Telegram, used by Iran's intelligence service to spy on dissidents.
Premier Medical Group Data Breach Impacts 280,000
Premier Medical Group confirmed a data breach from June 2026, where hackers accessed sensitive patient information including names, contact details, and health insurance data.