Security news.
Today's security landscape is marked by widespread exploitation of critical vulnerabilities in popular software and infrastructure, with several zero-days actively leveraged by threat actors. Additionally, the increasing integration of AI continues to shape both attack methods and defense strategies, highlighting new risks and research efforts.
Check Point Security Gateway VPN RCE Actively Exploited
Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) flaw in the VPN certificate-handling functionality of its Security Gateway product.
Critical WordPress Flaw (CVE-2026-87902) Exploited for Code Execution
Threat actors are actively exploiting a critical WordPress vulnerability to write and execute arbitrary files, moving beyond initial probing of vulnerable sites.
F5 Patches BIG-IP APM Zero-Day Exploited in RCE Attacks
F5 has released security updates to address a critical BIG-IP APM zero-day (CVE-2026-94127) actively exploited for unauthenticated remote code execution on OAuth authorization servers.
MikroTrick Chain Exploits MikroTik Routers Without Authentication
A chain of two MikroTik RouterOS SSH vulnerabilities (CVE-2026-67279, CVE-2026-86060), dubbed MikroTrick, allows attackers to take full administrative control of internet-exposed routers without a password.
Malicious Terraform Providers Deliver Go Malware via HashiCorp Registry
Researchers found Go-based malware distributed through malicious Terraform providers and Go Modules hosted on the centralized HashiCorp registry, marking a new distribution vector for threat actors.
Malicious AI Agents Steal 600K Credit Cards in Skimming Campaign
A financially motivated threat actor is utilizing open-source AI agent frameworks to target hundreds of online retailers, compromising over 100 sites and stealing more than 600,000 credit card records.
New cPanel Flaw Allows Root Code Execution from Hosting Account
A critical flaw in cPanel's CalDAV and CardDAV service (and another in its WP Toolkit plugin) allows any hosting account to run code as root and gain full server control; patches are released.
Exploit Released for Unpatched Ubuntu Linux Container Escape Flaw
An exploit has been released for CVE-2026-80521, a use-after-free vulnerability in the Linux kernel's AF_UNIX socket subsystem, allowing container escape to host root, with Ubuntu LTS releases currently unpatched.