Security news.
Threat actors are actively weaponizing newly disclosed vulnerabilities across enterprise platforms, with critical flaws in Atlassian and SonicWall appliances demanding immediate patch deployment. Federal agencies have also issued alerts regarding large-scale credential harvesting operations targeting network edge devices alongside severe enterprise data breaches. Meanwhile, major security updates have arrived for both Chrome and Android to mitigate critical code execution and privilege escalation risks.
Atlassian Pre-Auth Flaw Exploited in the Wild
Attackers have begun actively targeting a critical unauthenticated arbitrary file access flaw (CVE-2026-21589, CVSS 9.3) impacting Jira, Confluence, Bitbucket, and other Data Center platforms within hours of public disclosure.
SonicWall Issues Hotfix for Max-Severity SMA1000 Flaw
SonicWall has warned administrators of a maximum-severity server-side request forgery (SSRF) vulnerability affecting SMA1000 series appliances and urged prompt remediation.
FBI Warns of Active FortiBleed Credential Harvesting
The FBI and Secret Service issued a joint alert warning that the FortiBleed campaign remains active against Fortinet FortiGate firewalls and SSL-VPNs, harvesting over 86,000 device credentials.
Chrome 155 Patches 247 Security Vulnerabilities
Google released Chrome 155 to address a massive batch of vulnerabilities, notably resolving four critical use-after-free flaws in Browser, Navigation, Track, and Chromecast components.
Android October 2026 Security Updates Address 25 Flaws
Google’s monthly Android security bulletin remediates 25 vulnerabilities, including a critical privilege escalation bug located in the core Android System component.
ASOS Discloses Data Breach After Rogue App Alerts
Fashion retailer ASOS confirmed a security breach after unauthorized actors compromised a third-party communication channel, pushed rogue notifications to users, and claimed theft of customer data.
Arizona Court System Breach Impacts Over 1 Million People
The Arizona Supreme Court revealed that a cyberattack exposed the personal information of more than 1 million individuals spanning records dating back up to 30 years.
Ninja Forms Plugin Flaw Exploited to Backdoor WordPress Sites
Threat actors are actively exploiting stored cross-site scripting vulnerabilities in WordPress plugins Ninja Forms and WPC Product Bundles to install persistent backdoors and generate administrative accounts.