date / Author
source
title
short description
attacks and breaches
9/3/2026 Ionut Arghire
Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys.
The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek.
technology and tools
9/3/2026 Kevin Townsend
Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review.
The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek.
technology and tools
9/3/2026 Kevin Townsend
AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks.
The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek.
attacks and breaches
9/3/2026 Ionut Arghire
153 Million Driver License Images Offered on Dark Web
Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net.
The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek.
vulnerabilities and exploits
9/3/2026 Ionut Arghire
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek.
technology and tools,vulnerabilities and exploits
9/3/2026 Ionut Arghire
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass.
The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared first on SecurityWeek.
vulnerabilities and exploits
9/3/2026 Mayura Kathir
Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems
A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can automatically push a multi-stage VBScript malware chain to newly connected Windows endpoints. Once deployed, the clients repeatedly spawned wscript.exe to execute four scripts 1.vbs, 2.vbs, 3.vbs, and 4.vbs from ScreenConnect-related temporary locations. The behavior is […]
The post Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
technology and tools
9/3/2026 Divya
Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows […]
The post Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
vulnerabilities and exploits
9/3/2026 Divya
Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell
A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This vulnerability allows an attacker to dump the Windows Security Account Manager (SAM) database and launch a shell running as NT AUTHORITY\SYSTEM. The researcher behind the repository, known as MSNightmare, claims that the issue affects fully patched installations […]
The post Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
mobile security
9/3/2026 Mayura Kathir
StreamRAT Abuses Android Accessibility, MediaProjection and HVNC for Full Device Takeover
StreamRAT, a newly identified Android banking trojan distributed through fake free-TV streaming advertisements on Meta and TikTok. The campaign, tracked as “Steamtv Esp.,” primarily targeted Spanish-speaking Android users and exposed an estimated 570,000 Meta users between June 11 and July 3, 2026. The operation highlights the continued effectiveness of piracy-themed social engineering. Victims who clicked […]
The post StreamRAT Abuses Android Accessibility, MediaProjection and HVNC for Full Device Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
vulnerabilities and exploits
9/3/2026 Divya
WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover
A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection vulnerabilities, leading to remote code execution and complete website takeover. This issue, tracked as CVE-2026-19949, impacts the widely used All-in-One WP Migration and Backup plugin developed by ServMask. Wordfence has rated the vulnerability 8.8 out of […]
The post WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
vulnerabilities and exploits
9/3/2026 Divya
Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection
Security researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated attackers to execute code remotely via SQL injection. This vulnerability, tracked as CVE-2026-9586, affects internet-exposed Switchvox enterprise VoIP systems and was addressed in Switchvox version 8.4.0.2. Sangoma Switchvox RCE Flaw Zach Hanley, a researcher at Horizon3.ai, revealed that this […]
The post Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
attacks and breaches
9/3/2026 Zeljka Zorz
Thomson Reuters reveals breach that exposed U.S. and Canadian court records
Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published the disclosure publicly on Wednesday, along with separate notification pages for affected individuals in the United States and Canada. What happened, and when Thomson Reuters said it discovered unauthorized activity involving certain C-Track … More →
The post Thomson Reuters reveals breach that exposed U.S. and Canadian court records appeared first on Help Net Security.
technology and tools
9/3/2026 Sinisa Markovic
Google’s Gemini 3.8 Flash takes on bigger AI models at a lower cost
Google has introduced Gemini 3.8 Flash, available to developers today, and a gated sibling, Gemini 3.8 Flash Cyber, reserved for vetted security teams. “Our 3rd Flash release in just 6 wks,” Google CEO Sundar Pichai said on X, adding that it makes sizable gains over 3.7 Flash in software engineering, agentic work, and multi-step reasoning. On the DeepSWE v1.1 benchmark, Google says it beats most larger frontier models at solving complex engineering problems end to … More →
The post Google’s Gemini 3.8 Flash takes on bigger AI models at a lower cost appeared first on Help Net Security.
laws, regulations and policies,vulnerabilities and exploits
9/3/2026 Sinisa Markovic
Russian man indicted for spreading malware to 80,000 freelancers
A Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by a federal grand jury in California. Searzhudin Tamirlanovich Aktulaev, 40, faces charges of conspiracy, transmission of malicious code, and aggravated identity theft, among other counts, the Department of Justice said. He was arrested in Cyprus in May 2025 and extradited to the US in August 2026. From at least June 2016 … More →
The post Russian man indicted for spreading malware to 80,000 freelancers appeared first on Help Net Security.
technology and tools
9/3/2026 Sinisa Markovic
Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms
Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Institute of Science and Technology (KAIST), working with the National University of Singapore and Singapore Management University, has built a small LED accessory that tries to answer … More →
The post Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms appeared first on Help Net Security.
technology and tools
9/3/2026 Anamarija Pogorelec
Your AI agent’s system prompt is not a security control
An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a fellow at the SANS Institute, put the fix one layer down: scope the query to the user’s permissions at retrieval time, inside the role-based or attribute-based access system … More →
The post Your AI agent’s system prompt is not a security control appeared first on Help Net Security.
technology and tools
9/3/2026 Mirko Zorz
When AI quietly breaks things, who pays?
David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance disclosures in applications can turn into warranties an insurer uses to deny a claim, who should sign off on AI use questions, when the claim clock starts for slow-building model degradation, and how … More →
The post When AI quietly breaks things, who pays? appeared first on Help Net Security.
technology and tools
9/3/2026 Divya
Claude AI Can Now Control macOS and Windows Computers to Click, Type and Open Apps
Anthropic has enhanced Claude’s desktop automation capabilities, enabling the AI assistant to operate directly on macOS and Windows computers through Claude Cowork and Claude Code. When this feature is enabled, Claude can navigate a visible screen, click controls, type text, launch applications, open files, and work within browser-based or local tools if no dedicated connector […]
The post Claude AI Can Now Control macOS and Windows Computers to Click, Type and Open Apps appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
technology and tools
9/2/2026 Divya
Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance
Researchers have demonstrated that Anthropic’s Claude AI can assist in porting a remote code execution exploit between vulnerable models of WAGO programmable logic controllers (PLCs). However, this process requires significant human guidance, lengthy analysis sessions, and more than $500 in API usage. The experiment focused on CVE-2021-31886, a pre-authentication buffer overflow flaw in the Nucleus […]
The post Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
vulnerabilities and exploits
9/2/2026 Divya
Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover
Attackers are actively exploiting a critical authorization flaw in LiteLLM’s administrative API. This vulnerability allows low-privileged, read-only users to modify proxy configurations, expose sensitive secrets, and potentially gain full administrator control over affected servers. Researchers at Zenity Labs tracked approximately 3,900 requests targeting LiteLLM’s administration endpoints from February to June 2026, originating from 73 different […]
The post Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
mobile security,technology and tools
9/2/2026 Graham Cluley
Smashing Security podcast #483: This AI helps thieves steal your iPhone
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone.
Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just leave the door open?
All this and more in episode 483 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.
technology and tools
9/3/2026 Anamarija Pogorelec
Windows memory integrity switches on automatically for eligible devices in October 2026
Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory integrity is the layer that allows only trusted kernel-mode code and drivers to run, which is how it stops an attacker who is trying to compromise the Windows kernel and take control of core operating system functions. The … More →
The post Windows memory integrity switches on automatically for eligible devices in October 2026 appeared first on Help Net Security.
technology and tools
9/2/2026 Kevin Townsend
OpenLeash Adds a Human Check to Risky AI Agent Actions
The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain.
The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek.
technology and tools,vulnerabilities and exploits
9/2/2026 Sinisa Markovic
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026-62911 is a critical severity vulnerability, and Microsoft describes it as “authentication bypass by capture-replay in Microsoft Exchange Server,” which allows an authorized attacker to elevate privileges over a network. Microsoft released the fix on August 11, 2026, and … More →
The post Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) appeared first on Help Net Security.
vulnerabilities and exploits
9/2/2026 Zeljka Zorz
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unified communications platform built on the open-source Asterisk engine and aimed at small and medium-size businesses. It can be deployed on-premises, in the cloud, or on virtualized infrastructure. CVE-2026-9586, found in Sangoma Switchvox SMB Edition 8.3, allows attackers to … More →
The post Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) appeared first on Help Net Security.
laws, regulations and policies
9/2/2026 Kevin Townsend
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.
The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek.
vulnerabilities and exploits
9/2/2026 Ionut Arghire
Exploit Published for Fresh Cleo Harmony Vulnerability
The security defect allows remote attackers to bypass authentication through argument bearer manipulation.
The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek.
technology and tools
9/2/2026 Eduard Kovacs
Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards
Anthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse.
The post Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards appeared first on SecurityWeek.
vulnerabilities and exploits
9/2/2026 Zeljka Zorz
SonicWall SMA 1000 appliances under attack via zero-day flaws
Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built for scale. They are used regularly by medium to large enterprises, government agencies, and managed security service providers. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) flaw in the Appliance Work Place interface, and allows … More →
The post SonicWall SMA 1000 appliances under attack via zero-day flaws appeared first on Help Net Security.
technology and tools
9/2/2026 Eduard Kovacs
OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems.
The post OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold appeared first on SecurityWeek.
vulnerabilities and exploits
9/2/2026 Ionut Arghire
Chrome and Firefox Updates Patch Dozens of Vulnerabilities
The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.
The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
laws, regulations and policies
9/2/2026 Sinisa Markovic
Global sinkhole operation ends Sality botnet’s 23-year run
Sality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation cut Sality’s operator off from every infected machine still under their control. Sality first appeared in 2003 as a file-infecting virus, the kind that attaches itself to executable programs and spreads whenever an infected … More →
The post Global sinkhole operation ends Sality botnet’s 23-year run appeared first on Help Net Security.
vulnerabilities and exploits
9/2/2026 Eduard Kovacs
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.
The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek.
technology and tools
9/2/2026 Mirko Zorz
National Life Group CISO expects more vulnerabilities in six months than in thirty years
In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot keep up, and which compensating controls buy time when an immediate fix is not possible. It includes numbers from agentic AI in the security operations center, where four of five cases close without human escalation. The rest looks at questions … More →
The post National Life Group CISO expects more vulnerabilities in six months than in thirty years appeared first on Help Net Security.
technology and tools
9/2/2026 Mirko Zorz
Scareware ads keep running on Google’s transparency tool, even after they’re reported
A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to Google doesn’t mean the ad, or the domain behind it, stops running. The tool is called AdLens, and it comes out of a study that mined Google’s Ads Transparency Center, a public database Google built to satisfy transparency … More →
The post Scareware ads keep running on Google’s transparency tool, even after they’re reported appeared first on Help Net Security.
technology and tools
9/2/2026 Anamarija Pogorelec
Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud
Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, spent months working with Anthropic on a question their examiners care about more than benchmark scores. Scott DePasquale, the center’s president and chief executive, said those eight defined “what it would take to run the most capable frontier models inside a systemically important bank: who … More →
The post Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud appeared first on Help Net Security.
vulnerabilities and exploits,attacks and breaches
9/1/2026 BrianKrebs
FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.
technology and tools
9/1/2026 Melanie Johnson-Holliday
Forescout Research Tests Whether AI Can Create PLC Attacks
New research from Forescout’s Vedere Labs has demonstrated how artificial intelligence could begin to lower the barriers to developing sophisticated cyberattacks against industrial systems. The research set out to answer a potentially important question for operational technology (OT) security: can AI successfully adapt a remote code execution (RCE) exploit developed for one programmable logic controller […]
The post Forescout Research Tests Whether AI Can Create PLC Attacks appeared first on IT Security Guru.
technology and tools
9/1/2026 Sinisa Markovic
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks
A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ threat intelligence team. The campaign ran between January and April 2026 and reached more than 150 employees at more than 10 companies in different industries. The attackers registered external Microsoft Teams tenants with names built to resemble internal IT … More →
The post Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks appeared first on Help Net Security.
vulnerabilities and exploits
9/1/2026 Sinisa Markovic
Fake Claude Opus 5 app delivers malware and wipes its own tracks
A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository README using Claude Opus 5 branding and a “Free” hook (Source: Morphisec) “RevStealer is a Windows information stealer that is built to work quietly,” researchers explained. The campaign relies on social engineering, with victims steered to GitHub repositories that look … More →
The post Fake Claude Opus 5 app delivers malware and wipes its own tracks appeared first on Help Net Security.
vulnerabilities and exploits,technology and tools
9/1/2026 Eduard Kovacs
Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars
Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models.
The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek.
technology and tools,vulnerabilities and exploits
9/1/2026 Ionut Arghire
Hackers Start Exploiting Critical Langflow Vulnerability
Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.
The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek.
vulnerabilities and exploits
9/1/2026 Ionut Arghire
Five Venezuelans Plead Guilty in US Court to ATM Jackpotting
The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.
The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek.
attacks and breaches,vulnerabilities and exploits
9/1/2026 Ionut Arghire
Ransomware Gang Claims Nutex Health Data Breach
The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.
The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek.
vulnerabilities and exploits
9/1/2026 Eduard Kovacs
Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.
The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek.
vulnerabilities and exploits
9/1/2026 Ionut Arghire
WatchGuard Patches Critical Vulnerabilities
Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.
The post WatchGuard Patches Critical Vulnerabilities appeared first on SecurityWeek.