Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices.
The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software.
The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software.
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.
Email security company Proofpoint spotted the activity a week ago targeting various organizations, including government entities in the U.S. and Europe, and companies in the telecommunications, financial, hospitality, and aerospace sectors.
Laundry Bear exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability that allows executing arbitrary JavaScript in the browser context when users open a specially crafted email in the Outlook Web Access (OWA) app.
Email security company Proofpoint spotted the activity a week ago targeting various organizations, including government entities in the U.S. and Europe, and companies in the telecommunications, financial, hospitality, and aerospace sectors.
Laundry Bear exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability that allows executing arbitrary JavaScript in the browser context when users open a specially crafted email in the Outlook Web Access (OWA) app.
The source code for the Flying Eagle Android remote access trojan (RAT) framework is being shared on criminal Telegram channels. Researchers from Hunt.io and NetAskari have identified 170 internet servers linked to matching control panels and certificates.
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity.
EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels.
Cyber Dispatch™️
Cyberattack on Minnesota water systems.
A coordinated cyberattack struck more than 30 municipal water systems across Minnesota over the weekend, disrupting automated controls at treatment plants and water towers in communities including Braham, Plymouth, Maple Plain, and South St. Paul. State.
Cyber Dispatch™️
Cyberattack on Minnesota water systems.
Federal officials say the intrusions targeted operational technology such as programmable logic controllers and supervisory systems that manage pumps and monitoring, forcing some utilities to switch to manual operations.
Cyber Dispatch™️
Federal officials say the intrusions targeted operational technology such as programmable logic controllers and supervisory systems that manage pumps and monitoring, forcing some utilities to switch to manual operations.
John Israel, Minnesota’s chief information security officer, said hackers targeted roughly 36 systems as part of a breach first detected on Sunday.
Anthropic Reveals Rogue AI Models Hacked Three Companies During Testing
Anthropic disclosed that its AI models escaped testing environments and hacked three unsuspecting companies when inadvertently granted internet access, going undetected since April.
Anthropic disclosed that its AI models escaped testing environments and hacked three unsuspecting companies when inadvertently granted internet access, going undetected since April.
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks.
HackerOne will require a verified government ID to submit to any bug bounty program on its platform. Every account, new and existing, managed or unmanaged.
Its docs, updated today, cite "regulatory requirements." Verification runs through Veriff and must be renewed yearly; sessions over a VPN or on a jailbroken device are rejected, and under-18s can't verify at all.
Their vulnerability disclosure program stays open with no ID.
Its docs, updated today, cite "regulatory requirements." Verification runs through Veriff and must be renewed yearly; sessions over a VPN or on a jailbroken device are rejected, and under-18s can't verify at all.
Their vulnerability disclosure program stays open with no ID.
China is rapidly closing the satellite gap with the U.S., expanding its surveillance, navigation, and military space capabilities.
Its growing satellite network improves intelligence gathering, precision targeting, and tracking of U.S. forces, while advances in GPS alternatives, AI analysis, and anti-satellite weapons are raising concerns that Beijing could increasingly challenge U.S. military dominance in space.
Source: WSJ
Its growing satellite network improves intelligence gathering, precision targeting, and tracking of U.S. forces, while advances in GPS alternatives, AI analysis, and anti-satellite weapons are raising concerns that Beijing could increasingly challenge U.S. military dominance in space.
Source: WSJ
UK Department for Education confirms data breach affecting over 600,000 records.