Security news.
Today's security landscape is dominated by active exploitation targeting perimeter network devices and critical infrastructure. U.S. authorities and CISA have taken major disruption and directive actions against Chinese state-sponsored threat actors exploiting critical flaws, while vendors urgently push patches for severe edge appliance vulnerabilities. Concurrently, zero-day research milestones highlight ongoing software supply chain and device security risks.
SonicWall SMA1000 Zero-Day Under Active Exploitation
Attackers are actively targeting a maximum-severity flaw (CVE-2026-102255) in SonicWall SMA1000 appliances just days after vendor patches were made available.
CISA Orders Agencies to Patch Vulnerabilities Abused by Flax Typhoon
CISA added five security flaws, including maximum-severity ProFTPD vulnerability CVE-2015-3306, to its Known Exploited Vulnerabilities catalog after widespread abuse by China-linked threat actors.
Unpatched Zero-Days in AhsayCBS Exploited in the Wild
Threat actors are actively chaining CVE-2026-105133 and CVE-2026-105134 to bypass authentication and execute remote operating system commands on AhsayCBS backup software.
Citrix Urges Immediate Patching of Critical NetScaler RCE Flaw
Citrix has issued an urgent advisory for a memory overflow defect (CVE-2026-107406) affecting NetScaler ADC and Gateway appliances configured for SAML deployments.
FBI Disrupts Chinese Hacking Tools MicroScan and FishHub
U.S. law enforcement seized seven malicious domains operated by Flax Typhoon and associated state-sponsored groups targeting critical infrastructure and government entities.
Researchers Remotely Compromise Google Pixel 10 at Pwn2Own
Three separate research teams demonstrated remote zero-day execution on fully patched Google Pixel 10 devices, claiming more than half a million dollars in bounties.
Pre-Installed Android Firmware Malware Detected in 150+ Countries
The 'Midnight Mimosa' campaign has infected low-cost Android smartphones with factory-firmware trojans, enabling covert ad fraud and routing malicious residential proxy traffic.
Google Domains Targeted via Hijacked ccTLD Registries
Attackers compromised top-level country-code domains including .gh, .sl, and .as, allowing them to illicitly generate valid HTTPS certificates for core Google domains.