Security news.
Today's security landscape is marked by a flurry of critical vulnerabilities, including multiple zero-days actively exploited or with public PoCs, alongside significant data breaches and the continued evolution of AI-driven malware. Organizations are urged to prioritize patching and bolster defenses against sophisticated attacks leveraging novel techniques.
ShinyHunters Claims FBI Hack via PeopleSoft Zero-Day
The ShinyHunters extortion gang alleges it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, reportedly accessing internal services and stealing sensitive employee and applicant data.
Check Point Warns of Actively Exploited Management Server Zero-Day (CVE-2026-93616)
Check Point has released a fix for a critical zero-day vulnerability in its Security Management Server (CVE-2026-93616) that allows unauthenticated script execution, which attackers exploited in targeted attacks.
WordPress Patches Critical Code Execution Flaw
WordPress has released version 7.1.2 to fix a critical vulnerability that could allow an unauthenticated attacker to force a site to load external PHP files, potentially leading to remote code execution on some servers.
New Zero-Day PoC Blocks Microsoft Defender Updates
A security researcher released a proof-of-concept tool, "BigDiskBuster," that exploits a zero-day to fill disk space, preventing Microsoft Defender from installing platform and signature updates.
ClosedQuorum Windows Malware Uses AI for Attack Decisions
A novel Windows malware, ClosedQuorum, integrates Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously make decisions during the post-compromise stages of an attack.
Microsoft Disrupts EvilTokens AI-Assisted Phishing Service
Microsoft, in collaboration with industry partners, has dismantled the EvilTokens device-code phishing-as-a-service platform, which utilized AI at every stage and compromised over 12,000 Microsoft inboxes.
D-Link Warns of Max Severity Zero-Day in DIR-822A Routers (CVE-2026-86296)
D-Link has issued a warning regarding a maximum-severity zero-day vulnerability (CVE-2026-86296) with public exploit code affecting its legacy DIR-822A Wi-Fi routers, with no patch currently available.
Critical VeloCloud Orchestrator Flaw (CVE-2026-93952) Actively Exploited
An unauthenticated remote command injection vulnerability (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) is being actively exploited, particularly affecting certificate-based setups.