CISA Orders Emergency Patching For Cisco FMC Zero-Day Exploited Through Static Credentials post, juli 30, 2026juli 31, 2026 A newly disclosed vulnerability in Cisco Secure Firewall Management Center is being actively exploited in attacks, prompting the US Cybersecurity and Infrastructure Security Agency to order federal agencies to apply emergency fixes within days. Tracked as CVE-2026-20316, the vulnerability allows an unauthenticated remote attacker to sign in to an affected… Continue Reading
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack post, juli 29, 2026juli 31, 2026 The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in “a coordinated cyberattack.” The attacks occurred on Sunday and Monday, July 26 and 27, and targeted operational technology (OT) systems at local water utilities. Continue Reading
Ernst & Young data breach claimed by ShinyHunters extortion gang post, juli 27, 2026juli 29, 2026 The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack. Ernst & Young disclosed the breach earlier this month, saying a third-party support ticket system used by its IT personnel… Continue Reading
Critical GitLab Flaw Enables Remote Code Execution post, juli 26, 2026juli 27, 2026 Security researchers have published proof-of-concept exploit code for a remote code execution vulnerability affecting multiple versions of self-managed GitLab, sharply increasing the urgency for organizations that have not installed patches released in June 2026. The exploit chain allows an authenticated GitLab user with permission to commit changes to a project… Continue Reading
Russian State-Backed Threat Actor Exploits Zimbra Zero-Day To Steal Emails & Authentication Data post, juli 24, 2026juli 27, 2026 A Russian state-supported hacking group has been exploiting a previously unknown vulnerability in Zimbra Collaboration Suite to silently steal emails, passwords, two-factor authentication codes and corporate address books from government and commercial organizations across Western countries. The campaign, attributed to a threat group primarily known as Laundry Bear, has been… Continue Reading
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks post, juli 23, 2026juli 27, 2026 An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it… Continue Reading
Check Point Patches Actively Exploited SmartConsole Flaw Allowing Full Administrative Access post, juli 23, 2026juli 27, 2026 Check Point has released urgent security updates for three vulnerabilities affecting its firewall and security-management platforms, including a critical SmartConsole authentication bypass that attackers have already exploited against a small number of customers. The most serious vulnerability, tracked as CVE-2026-16232, could allow an unauthenticated remote attacker to obtain a valid… Continue Reading
OpenAI hackt ander AI-bedrijf, maar van ‘op hol geslagen AI’ is geen sprake post, juli 23, 2026juli 31, 2026 OpenAI heeft per ongeluk een ander AI-bedrijf gehackt. Dat gebeurde tijdens een test waarmee OpenAI wilde kijken hoe goed zijn AI-programma’s presteren op het gebied van cybersecurity. Nadat OpenAI zijn AI-programma’s veel vrijheid had gegeven om de test te voltooien, gebeurde iets wat niet de bedoeling was: ze verlieten de… Continue Reading
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack post, juli 22, 2026juli 27, 2026 Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. The threat actor has not publicly claimed the attack, but the Swiss company says that it received an extortion letter from Everest ransomware… Continue Reading
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure post, juli 22, 2026juli 27, 2026 The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control… Continue Reading