Security news.
Today's security news features a mix of critical vulnerabilities, active exploitation, and ongoing research into AI-driven threats. Multiple vendors, including D-Link and Zyxel, have released advisories for severe flaws, with some already under active attack by sophisticated threat actors. The cybersecurity community is also grappling with the implications of AI's role in both attack and defense strategies.
D-Link Warns of Max Severity Zero-Day in DIR-822A Routers
D-Link has issued a warning regarding a critical, unpatched zero-day vulnerability (CVE-2026-86296) with public PoC exploit code affecting its legacy DIR-822A Wi-Fi routers.
New Linux Kernel Flaw Impacts ARM64 KVM Guests
A newly discovered flaw in the Linux kernel's KVM virtualization code (CVE-2026-89775) for ARM64 processors allows KVM guests to gain read-write access to host memory, potentially leading to guest escape and host code execution.
New Windows Defender Zero-Day Blocks Antivirus Updates
A security researcher released a new Microsoft Defender zero-day exploit that prevents the antivirus from receiving updates, leaving systems vulnerable.
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
A Chinese threat actor has actively exploited a vulnerability in nearly 1,000 ZyXEL switches, exfiltrating sensitive information. CISA has added this flaw (CVE-2026-7273) to its Known Exploited Vulnerabilities catalog.
SharePoint Flaw Enables Authenticated RCE, Not Just Spoofing
A SharePoint Server vulnerability (CVE-2026-65660), initially downplayed by Microsoft as a spoofing flaw, has been revealed to enable authenticated remote code execution across SharePoint Server 2016, 2019, and Subscription Edition.
WordPress Patches 'Comment2Shell' RCE Vulnerability
WordPress has patched a critical "Comment2Shell" flaw (CVE-2026-93485) that could allow an anonymous attacker to achieve remote code execution on a site's server via a hidden script in a comment, triggered by an authenticated administrator.
The Closed Quorum: Inside the First Autonomous AI C2 Implant
Cisco Talos has discovered CLOSEDQUORUM, a malware binary exhibiting fully autonomous command and control (C2), representing a significant shift towards AI-integrated malware that can execute attack chains without direct operator involvement.
Malicious B-tree NPM Package Accumulates Millions of Downloads
The malicious npm package "indexed-btree" mimicked the legitimate "sorted-btree" and hid its malware trigger within a prototype method, accumulating millions of downloads before its removal.