Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

2+ day, 21+ hour ago   (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...

SecurityWeek
securityweek.com > critical-netscaler-vulnerability-exploited-in-attacks

Critical NetScaler Vulnerability Exploited in Attacks

3+ day, 19+ hour ago   (460+ words) Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks....

SecurityWeek
securityweek.com > widened-scan-turns-up-fourth-rogue-claude-cyber-incident

Widened Scan Turns Up Fourth Rogue Claude Cyber Incident

3+ day, 20+ hour ago   (816+ words) Anthropic is most concerned about Claude Mythos 5’s reckless behavior after recent incidents in which real systems were hacked. Anthropic disclosed a previously unreported incident involving unauthorized access to a real system, in a report that also revisits three cases…...

SecurityWeek
securityweek.com > organizations-warned-of-cisco-secure-fmc-exploitation

Organizations Warned of Cisco Secure FMC Exploitation

3+ day, 22+ hour ago   (578+ words) Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year. The security hole,…...

SecurityWeek
securityweek.com > fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

4+ day, 1+ hour ago   (436+ words) Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports. Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug…...

SecurityWeek
securityweek.com > ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

4+ day, 21+ hour ago   (489+ words) Industrial giants Schneider Electric, Siemens, and Aveva have published September 2026 Patch Tuesday advisories, informing customers about vulnerabilities found in their ICS products. Schneider Electric published four new security advisories and updated four others, including one originally released in 2019. The most…...

SecurityWeek
securityweek.com > new-phishing-attack-creates-malicious-pages-inside-the-victims-browser

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

4+ day, 22+ hour ago   (434+ words) Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. Future phishing campaigns may no longer involve a detectable physical web page. The attack flow…...

SecurityWeek
securityweek.com > adobe-patches-over-170-vulnerabilities-including-commerce-zero-day

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

5+ day, 13+ hour ago   (547+ words) Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score…...

SecurityWeek
securityweek.com > sap-patches-critical-extended-passport-processing-vulnerability

SAP Patches Critical Extended Passport Processing Vulnerability

5+ day, 17+ hour ago   (626+ words) Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. SAP released 20 new and updated security notes on Tuesday, including one that resolves a critical-severity memory corruption vulnerability. Tracked as…...

SecurityWeek
securityweek.com > mikrotik-patches-critical-flaws-chained-to-hack-routers

MikroTik Patches Critical Flaws Chained to Hack Routers

5+ day, 20+ hour ago   (570+ words) Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two…...