Security news.
Threat actors and federal agencies are escalating focus on enterprise infrastructure, with CISA issuing warnings for actively exploited flaws across Microsoft SharePoint, MikroTik, and WSO2. Meanwhile, secure file-sharing provider Kiteworks took the unprecedented step of urging clients to take systems offline ahead of an imminent cyberattack. In addition, critical vulnerabilities in widespread web software like WordPress Elementor and Roundcube Webmail require immediate administrative patching.
Kiteworks Urges Customers to Take Servers Offline Over Imminent Attack Threat
Following credible federal intelligence regarding an impending cyberattack, Kiteworks advised organizations globally to shut down secure file-transfer systems for several hours over the weekend.
CISA Adds Actively Exploited SharePoint and MikroTik Flaws to KEV Catalog
CISA warned of in-the-wild exploitation targeting Microsoft Office SharePoint (CVE-2026-65660, CVSS 8.8 code injection) and MikroTik RouterOS workflow enforcement issues (CVE-2026-67279).
Severe Elementor Plugin Flaw Enables WordPress Site Takeover
An unauthenticated cross-site request forgery (CSRF) vulnerability (CVSS 8.8) in the popular Elementor Website Builder allows attackers to silently generate rogue administrator accounts if an admin clicks a crafted link.
Critical WSO2 and Adobe Commerce Flaws Under Active Cyber Exploitation
CISA has added an actively abused critical path traversal bug in WSO2 API Control Plane (CVE-2026-5430, CVSS 9.8) alongside an Adobe Commerce authorization flaw (CVE-2026-71362) to its catalog.
Roundcube Pre-Auth SQL Injection Flaw Exploited in the Wild
Cybersecurity authorities are tracking active exploitation of CVE-2026-48842 (CVSS 8.1), a pre-authentication SQL injection vulnerability impacting the virtuser_query plugin in Roundcube Webmail.
Bitget Crypto Exchange Loses $351.6M to Suspected North Korean Threat Actors
Hackers breached backend systems and drained hot and warm cryptocurrency wallets belonging to exchange platform Bitget before unauthorized transfers could be fully contained.
OpenAI Discloses Data Leak Incident Involving Autonomous AI Agents
OpenAI revealed that autonomous AI agents conducting automated evaluations mistakenly uploaded user-provided images directly to public third-party hosting services.
ShinyHunters Compromises Clop Ransomware Leak Site via Grav CMS
The Clop ransomware syndicate was forced to migrate to a new dark web leak site after attackers leveraged an unauthenticated path traversal flaw in Grav CMS to deface and breach the infrastructure.