← Latest brief

Security news.

·Afternoon Brief

Threat actors are actively exploiting freshly disclosed zero-day and unpatched flaws in WordPress, Roundcube, and enterprise VPN appliances. Meanwhile, CISA has added high-impact vulnerabilities in TeamCity, WSO2, and Adobe Commerce to its Known Exploited Vulnerabilities catalog as ransomware groups accelerate automated attacks. Developers and administrators should immediately patch public-facing services and audit autonomous AI agent permissions.

THNEXPLOIT
16h agoREAD

WordPress Under Active Attack via Critical CVE-2026-87902

Threat actors began exploiting an unauthenticated remote code execution vulnerability (CVSS 9.2) in WordPress within hours of public disclosure. The flaw allows attackers to manipulate page-template inclusion to execute arbitrary PHP code.

BLEEPINGEXPLOIT
8h agoREAD

Hackers Exploit High-Severity Roundcube Webmail Flaw

The Canadian Centre for Cyber Security warns that a code injection vulnerability patched in May is now facing active in-the-wild exploitation. Unpatched Roundcube servers risk full compromise via malicious email processing.

BLEEPINGRANSOMWARE
11h agoREAD

Ransomware Gangs Weaponize Patched JetBrains TeamCity Flaw

CISA issued a warning that ransomware operators are actively exploiting a critical TeamCity vulnerability originally disclosed in July. Administrators must verify on-premises build servers are running the latest patched release.

CISAKEV
10h agoREAD

CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog

CISA has added CVE-2026-5430 (WSO2 path traversal) and CVE-2026-71362 (Adobe Commerce and Magento authorization bypass) to its catalog following evidence of active exploitation. Federal agencies and enterprises have strict deadlines to apply vendor remediations.

BLEEPINGRCE
1d agoREAD

Check Point Confirms Exploitation of Security Gateway VPN RCE

Threat actors are actively targeting CVE-2026-85102, a pre-authentication remote code execution flaw within the VPN certificate-handling functionality of Check Point Security Gateways. Organizations are urged to immediately apply the vendor-issued emergency hotfix.

SECURITYWEEKRCE
11h agoREAD

SolarWinds Patches Critical Unauthenticated RCE Bugs

SolarWinds addressed two critical vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, affecting Observability Self-Hosted deployments. Both flaws can be triggered remotely without authentication to execute arbitrary code.

THNPATCH
3h agoREAD

Unpatched OnePlus OxygenOS Flaws Grant Root Without Permissions

Researchers revealed an exploit chain affecting OnePlus and OPPO devices running OxygenOS that allows any newly installed, unprivileged app to gain full root access. The vendor confirmed multiple device families remain affected while patches are finalized.

THNBREACH
6h agoREAD

Documentation Placeholder third-party.com Hijacked for ClickFix Attacks

The domain "third-party[.]com," widely cited as an example URL across thousands of developer repositories and guides, was weaponized to serve ClickFix PowerShell lures to Windows visitors. Developers are advised to scrub project documentation and substitute reserved domains like example.com.

Generated twice daily from public security RSS feeds. Informational only.