Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

11/09/2026 0 Comments 0 tags

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

11/09/2026 0 Comments 0 tags

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

11/09/2026 0 Comments 0 tags

A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims’

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

11/09/2026 0 Comments 0 tags

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

10/09/2026 0 Comments 0 tags

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much.

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

10/09/2026 0 Comments 0 tags

Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

10/09/2026 0 Comments 0 tags

The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

10/09/2026 0 Comments 0 tags

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

10/09/2026 0 Comments 0 tags

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

10/09/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive