Security news.
Threat actors are rapidly weaponising newly disclosed flaws, with critical Atlassian vulnerabilities under active attack within hours of public exploit releases. Network infrastructure remains heavily targeted as vendors issue urgent fixes for root-level switch takeovers and appliance hijacking, while supply chain and firmware compromises pose expanding operational risks.
Atlassian Data Center Flaw Under Active Exploit
Threat actors have begun actively targeting CVE-2026-21589, a critical pre-authentication arbitrary file read vulnerability affecting self-hosted Atlassian Data Center products, following the release of public proof-of-concept exploits.
Cisco Warns of Root Takeover Flaws in Nexus Switches
Cisco released security advisories addressing five critical vulnerabilities in its NX-OS network operating system that can allow unauthenticated attackers to execute arbitrary code with root privileges on Nexus switches.
Attackers Weaponise 'FortiBleed' to Lock Administrators Out
Threat actors are actively exploiting Fortinet appliances to seize administrative access, deleting existing accounts and altering passwords to lock out legitimate administrators.
Critical Vulnerabilities Patched in SonicWall and Splunk
Splunk and SonicWall have issued security patches for critical and high-severity flaws that could allow attackers to bypass authentication, elevate privileges, and execute remote code.
FBI Exposes Chinese Cyber Firm's Mass Email Interception Portal
The FBI and allied agencies revealed that Chinese cybersecurity firm Integrity Technology Group ran a portal distributing stolen government, healthcare, and infrastructure emails harvested via mass automated vulnerability scanning.
FakeGit Campaign Spreads SmartLoader Across 17,000 GitHub Repos
The resurrected FakeGit malware operation has seeded over 17,600 malicious GitHub repositories distributing SmartLoader and the StealC infostealer to infect software developers.
Pre-Installed Firmware Malware Found on Budget Android Devices
The 'Midnight Mimosa' campaign was uncovered shipping budget Android smartphones with pre-installed firmware malware that silently installs apps and turns consumer devices into residential proxies.
Ransomware Remediation CEO Charged in $19M Secret Decryption Fraud
The owner of ransomware incident response firm MonsterCloud was charged by the DOJ for allegedly billing victims millions under the claim of using proprietary recovery technology while secretly paying ransom demands to attackers.