A pair of critical, unauthenticated zero-day vulnerabilities in Citrix NetScaler are being actively exploited right now and with roughly 23,000 internet-exposed devices worldwide, this is a "patch today, not next sprint" moment that shows exactly why continuous vulnerability management can't be a once-a-quarter checkbox for any growing business.
Threat update
A newly disclosed vulnerability in WordPress Core, nicknamed Click2Shell, allows an attacker to take control of a WordPress website if a logged-in administrator simply opens a specially crafted link. No further clicks, prompts, or approvals are needed. WordPress fixed the issue in version 7.1.1 and backported the fix to every supported branch back to 4.7. Because proof-of-concept code is now public, any organization running WordPress should confirm its sites are updated today.
Threat update
A newly detailed Linux kernel vulnerability, tracked as CVE-2026-43502 and nicknamed ZcopyReaper, allows an unprivileged local user to escalate to full root control by abusing a memory-handling error in the kernel's Reliable Datagram Sockets (RDS) component. The flaw has existed since Linux kernel 4.17, working exploit code has been published, and patched kernels are available from major distributions. Organizations running Linux servers, cloud workloads, or Linux-based appliances should confirm patch status now.
Threat update
A newly documented malware family named KATARU is hijacking internet-facing Linux devices, including routers and other IoT equipment, by guessing weak or default Telnet passwords. Once inside, it takes root-level control, embeds itself so it survives reboots, and enlists the device in a Mirai-style botnet used for large-scale DDoS attacks. Any organization with connected devices that are exposed to the internet, unpatched, or protected by default credentials should review its exposure now.
Threat update
A newly disclosed security issue affecting ConnectWise ScreenConnect could allow files to be transferred and executed during an active remote-support session without the authorization or confirmation normally expected in certain circumstances. ConnectWise has released ScreenConnect 26.6.5 to address the vulnerability, identified as CVE-2026-84869, and recommends affected organizations update as soon as possible.
Threat update
Cybersecurity researchers have identified a threat actor that leverages artificial intelligence throughout the attack lifecycle to conduct search engine optimization (SEO) fraud, steal data, and maintain persistence in compromised environments.
Threat update
Threat actors are actively targeting SonicWall SMA1000 appliances by exploiting two zero-day vulnerabilities affecting models 6210, 7210, and 8200v.
A live, actively targetable flaw in on-premises Microsoft Exchange is sitting unpatched on roughly 22,000 servers worldwide and for many small and mid-size businesses, the safety net (extended security support) runs out next month, turning a patching task into a hard deadline.
Threat update
Threat actors are actively targeting SonicWall SMA1000 appliances by exploiting two zero-day vulnerabilities affecting models 6210, 7210, and 8200v. Review this Cybersecurity Threat Advisory to protect your systems and mitigate risk.
Threat update
Security researchers have identified a phishing campaign that uses Microsoft Teams messages impersonating IT support staff to distribute a newly discovered malware known as SynkLoader. Read this Cybersecurity Threat Advisory to understand the risks associated with SynkLoader, identify potential exposure, and learn the recommended steps to protect your users and systems.
Threat update
An authentication bypass zero-day vulnerability, tracked as CVE-2026-20182 with a maximum CVSS score of 10.0, has been identified in Cisco Catalyst SD-WAN Controller and Manager. The vulnerability allows unauthenticated attackers to gain the highest level of administrative access to affected systems without valid credentials and is currently under active exploitation by UAT-8616, a persistent and sophisticated threat group previously linked to multiple zero-day campaigns targeting Cisco network edge technologies. Continue reading this Cybersecurity Threat Advisory to learn how to minimize your risk and protect your environment.
Threat update
SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds.
AI phishing attacks are making familiar cyber scams faster, more convincing, and harder for employees to recognize. Recent 2026 threat intelligence shows attackers expanding beyond email into Microsoft Teams, voice calls, trusted cloud services, and highly personalized messages. For businesses, protecting Microsoft 365 identities and training employees to verify unusual requests has become increasingly important.
Mandiant has identified a novel method to bypass browser isolation technology and achieve command-and-control operations through QR codes.
The FBI warns that scammers are increasingly using artificial intelligence to improve the quality and effectiveness of their online fraud schemes, ranging from romance and investment scams to job hiring schemes.
Multinational telecommunications giant BT Group (formerly British Telecom) has confirmed that its BT Conferencing business division shut down some of its servers following a Black Basta ransomware breach.
Threat update
Recent reports have uncovered that a threat actor known as RomCom has been exploiting two zero-day vulnerabilities, one in Mozilla Firefox and another in Microsoft Windows, to deploy their proprietary backdoor malware. These vulnerabilities, CVE-2024-9680 and CVE-2024-49039, have been actively targeted in attacks across Europe and North America. Continue reading this Cybersecurity Threat Advisory to learn how to defend against RomCom.
Threat update
A security vulnerability in 7-Zip allows remote attackers to bypass defenses and execute malicious code via specially crafted archives. Read this Cybersecurity Threat Advisory to learn how to mitigate your risk from this new threat.
