Global Threat Level: CRITICAL

12 critical threats detected in the last 24 hours. 1 active zero-day reported. Active threat actors: Conti. Immediate review of affected systems recommended.

463
CVEs Tracked
224
Critical Threats
279
High Threats
8
Threat Actors
1 Active Zero-Day

Latest Intelligence

CRITICALVulnerability
Verified

NVD CRITICAL: CVE-2026-82042 — UTMStack before 11.2.16 contains an authentication bypass vulnerability that all...

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtai

8h agoGlobalNIST NVDCVE-2026-82042
CRITICALVulnerability

NVD CRITICAL: CVE-2026-82041 — UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMInc...

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, res

CVE-2026-82041
NIST NVD
MEDIUMVulnerability

Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing

The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Schneier on Security
MEDIUMVulnerability

Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus

The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.

The Record
MEDIUMVulnerability

RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail

The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.

Dark Reading
MEDIUMVulnerability

Bipartisan backlash to ALPRs grows as two high-profile bills are introduced

Republican Sen. Josh Hawley has new legislation on limiting automated license plate readers (ALPRs), while Democratic Sens. Bernie Sanders and Jeff Merkley, with Rep. Alexandria Ocasio-Cortez, have teed up a broader bill.

The Record
CRITICALVulnerability

NVD CRITICAL: CVE-2023-54405 — H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud plat...

H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token pa

CVE-2023-54405
NIST NVD
HIGHData Breach

Frontline Education breach exposes school district employee data

Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]

BleepingComputer
HIGHRansomware

Warlock ransomware breach SharePoint in water, telecom operator attacks

The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]

BleepingComputer
MEDIUMAi

The legal questions raised by agentic AI hacks

Experts and policymakers want AI companies to face consequences for agentic hacks. There may not be a clear-cut answer under existing laws and regulations. The post The legal questions raised by agentic AI hacks appeared first on CyberScoop .

CyberScoop
CRITICALVulnerability

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw

The Hacker News
MEDIUMApt

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

The Hacker News
CRITICALVulnerability

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an

CVE-2026-63688
The Hacker News

Live Activity

Threat Alerts

Real-time alerts for the threats that matter to you. Choose your severity levels and threat categories.