
ConnectWise issues mitigation for unpatched ScreenConnect flaw
ConnectWise has shared interim steps to reduce risk from a new vulnerability in its ScreenConnect remote-access software, with a fix due later this week.
Incidents, vulnerabilities, abuse and certificates.

ConnectWise has shared interim steps to reduce risk from a new vulnerability in its ScreenConnect remote-access software, with a fix due later this week.

A Google Cloud engineer accidentally disconnected all fiber-optic cables in a us-central1-b zone during routine maintenance, causing a 4-hour outage for virtual machines and elevated packet loss. Google confirmed the incident stemmed from procedural failure.

Cloudflare's early-access Vulnerability Discovery and Remediation service uses OpenAI models to detect and prioritize code vulnerabilities based on production exposure, proposing tailored patches and WAF rules for customer review.

Attackers breached Coder's Cloudflare infrastructure to distribute malicious Terraform modules containing credential-stealing code to developers.

Hewlett Packard Enterprise has released a security update for ArubaOS-CX to address a critical remote code execution vulnerability, mitigating potential network compromise risks.

Hackers are exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, to deploy reverse shells and gain remote code execution on affected systems.

DTLS 1.3, finalized in 2022, reduces handshake latency by 50% and introduces support for NIST-standardized post-quantum cryptography, addressing a critical gap in DTLS 1.2. wolfSSL has offered a production-ready implementation since the RFC's publication.

Security teams detected active exploitation of CVE-2026-82329, a critical authentication-bypass vulnerability in JFrog Artifactory, shortly after the vendor released a fix. Attackers are generating administrative credentials and probing internal topologies on internet-facing systems.

Hackers hijacked BGP routes for Virtualizor's update servers, replacing legitimate VPS management software updates with malware in a targeted supply-chain attack.

Nearly 22,000 Microsoft Exchange servers exposed to the internet remain unpatched against a high-severity authentication bypass vulnerability, leaving all user mailboxes open to hijacking.

Microsoft is investigating a service disruption affecting Exchange Online email delivery and authentication, with no estimated resolution time disclosed.

Security researchers have identified a new technique used by the Chinese state-linked Fire Ant hacking group to turn Cisco IOS XR routers into covert data exfiltration channels via undocumented GRE tunnels.

PaperCut has released a second emergency security update for its NG and MF software after researchers discovered ways to bypass the initial patch for two actively exploited vulnerabilities.

cPanel released patches for a critical vulnerability allowing authenticated users with domain permissions to execute arbitrary code as root, affecting all supported versions of its control panel software.

PaperCut has issued an urgent warning after attackers exploited an unpatched vulnerability in its NG and MF print management platforms, with no fix yet available.

CISA has ordered federal agencies to patch a critical Citrix NetScaler remote code execution vulnerability being actively exploited in attacks, with a deadline of this Saturday.

The US Treasury designated Italy-based Autistici Inventati for providing encrypted email, hosting, and digital tools to designated terrorist organizations, including the PKK and fronts for the Popular Front for the Liberation of Palestine. The action freezes all US assets and prohibits transactions with the provider.

Attackers are actively targeting WordPress sites using the miniOrange SAML 2.0 Single Sign On plugin, exploiting two critical authentication bypass vulnerabilities to forge SAML responses and log in as administrators.

Research by Interisle Consulting Group and ICANN indicates that up to 20% of new generic top-level domain registrations in 2025 may have been controlled by malicious actors, prompting calls for stronger contractual safeguards and risk-based KYC measures across the DNS ecosystem.

Microsoft has released a fix for a critical vulnerability in Entra ID after confirming in-the-wild exploitation. The flaw allows attackers to bypass authentication controls in the identity and access management service.