Security news.
Threat actors are actively leveraging zero-day vulnerabilities across critical enterprise infrastructure, prompting emergency advisories and additions to CISA's catalog. In parallel, significant law enforcement actions dismantled a prominent extortion group while major data breaches and exchange heists were confirmed. Defenders must prioritize patching exposed perimeter systems, specifically Cisco SD-WAN appliances and Citrix NetScaler gateways.
CISA Adds Cisco SD-WAN Manager Auth Bypass to KEV
CISA added CVE-2026-76504, a critical CVSS 9.8 authentication bypass affecting Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities catalog following confirmed active exploitation in the wild. Federal agencies have been mandated to patch immediately to prevent unauthenticated remote access.
Citrix NetScaler Zero-Days Under Active Attack
Threat intelligence researchers report in-the-wild exploitation of Citrix NetScaler zero-day vulnerabilities CVE-2026-88771 (pre-auth command injection) and CVE-2026-88772 (pre-auth memory overflow). Organizations running affected appliances should immediately verify exposure and apply vendor security updates.
Zimbra Flaw Exploited Prior to Public Disclosure
An unauthenticated command injection vulnerability in Zimbra mail servers (CVE-2026-73570) was weaponized in the wild before public disclosure. Attackers can trigger the exploit zero-click via specially crafted email payloads to execute code on internet-facing servers.
Public PoC Released for Exploited Apple CoreGraphics Flaw
Security researchers released a working proof-of-concept for CVE-2026-86950, an Apple memory corruption vulnerability that Apple confirmed was targeted in real-world attacks. Delivery mechanisms are reportedly taking advantage of crafted font rendering via malicious PDF files.
Bitget Confirms $387.5M Theft via Third-Party Zero-Day
Cryptocurrency exchange Bitget revealed that a massive $387.5 million compromise was executed through a zero-day exploit targeting third-party security software. The attackers leveraged custom tradecraft to bypass protections and siphon funds.
Pentagon HR Breach Exposes 3 Million Records
The U.S. Department of Defense is notifying over 3 million military personnel that sensitive records were compromised during an intrusion into an internal human resources management system. The stolen data includes highly sensitive personal records collected by the Defense Manpower Data Center.
Kiteworks Patches Max-Severity EPG Injection Vulnerability
Kiteworks shipped critical patches addressing 126 vulnerabilities across its secure file sharing platforms, headlined by a maximum-severity code injection flaw in its Email Protection Gateway. Administrators are urged to patch immediately or temporarily isolate vulnerable servers.
International Police Disrupt KillSec Ransomware Gang
Law enforcement seized the data leak infrastructure and command servers of the KillSec extortion operation in a multi-nation sweep dubbed Operation KillSwitch. Authorities arrested three suspects, including a 16-year-old identified as the group's administrator, recovering 110 terabytes of exfiltrated victim data.