CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines

21/04/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three flaws impacting Cisco Catalyst SD-WAN Manager, citing

SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files

20/04/2026 0 Comments 0 tags

A critical security vulnerability has been disclosed in SGLang that, if successfully exploited, could result in remote code execution on susceptible systems. The vulnerability, tracked as CVE-2026-5760, carries a CVSS

⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More

20/04/2026 0 Comments 0 tags

Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver

Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain

20/04/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a critical “by design” weakness in the Model Context Protocol’s (MCP) architecture that could pave the way for remote code execution and have a cascading effect

Why Most AI Deployments Stall After the Demo

20/04/2026 0 Comments 0 tags

The fastest way to fall in love with an AI tool is to watch the demo. Everything moves quickly. Prompts land cleanly. The system produces impressive outputs in seconds. It

Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems

20/04/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a new malware called ZionSiphon that appears to be specifically designed to target Israeli water treatment and desalination systems. The malware has been codenamed ZionSiphon by

Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

20/04/2026 0 Comments 0 tags

Web infrastructure provider Vercel has disclosed a security breach that allows bad actors to gain unauthorized access to “certain” internal Vercel systems. The incident stemmed from the compromise of Context.ai,

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

18/04/2026 0 Comments 0 tags

Grinex, a Kyrgyzstan-incorporated cryptocurrency exchange sanctioned by the U.K. and the U.S. last year, said it’s suspending operations after it blamed Western intelligence agencies for a $13.74 million hack. The

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

18/04/2026 0 Comments 0 tags

Threat actors are exploiting security flaws in TBK DVR and end‑of‑life (EoL) TP-Link Wi-Fi routers to deploy Mirai-botnet variants on compromised devices, according to findings from Fortinet FortiGuard Labs and

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

17/04/2026 0 Comments 0 tags

Huntress is warning that threat actors are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges in compromised systems. The activity involves the exploitation of three vulnerabilities