Security news.
Widespread active exploitation of network perimeter appliances and cryptographic libraries dominates today's security landscape, led by dual zero-days targeting Citrix NetScaler deployments worldwide. Security teams also face critical updates addressing browser escape vulnerabilities, high-severity DTLS flaws in OpenSSL, and actively exploited Apple zero-days added to CISA's catalog.
Citrix NetScaler Zero-Days Under Active Global Exploitation
Threat actors are actively weaponizing vulnerabilities CVE-2026-88771 and CVE-2026-88772 to gain root access, deploy custom web shells, and breach government and financial organizations.
CISA Adds Actively Weaponized Apple Zero-Day to KEV Catalog
Federal agencies have been ordered to patch CVE-2026-86950, a critical out-of-bounds write flaw affecting macOS and iOS that is undergoing targeted in-the-wild exploitation.
Bitget Crypto Exchange Breached for $387.5 Million via Security Software Zero-Day
Attackers compromised internal systems after exploiting an undisclosed third-party security software flaw to orchestrate a massive cryptocurrency theft.
OpenSSL Patches High-Severity DTLS Memory-Leak Vulnerability
Flaws in Datagram Transport Layer Security handshake retransmissions can allow remote attackers to extract unencrypted heap memory or trigger application crashes.
Chrome and Firefox Issue Patches for Over 100 Flaws
Major updates from Google and Mozilla resolve multiple high-severity vulnerabilities capable of facilitating remote code execution and browser sandbox escapes.
TeamViewer Urges Immediate Patching for High-Severity Flaws
Administrators are advised to rapidly deploy updates resolving serious vulnerabilities across both client and host versions of the remote desktop software.
Spectre-v2 Branch Target Reuse Flaw Bypasses Existing Defenses
Researchers revealed a CPU transient execution attack that exposes JIT engines and kernels across major processor vendors, leaking Linux root password hashes within minutes.