
Kiteworks orders global 6-hour server shutdown over zero-day threat
Kiteworks instructed all customers to shut down servers for six hours on Saturday after receiving threat intelligence about a potential zero-day attack, with no patch available.
Incidents, vulnerabilities, abuse and certificates.

Kiteworks instructed all customers to shut down servers for six hours on Saturday after receiving threat intelligence about a potential zero-day attack, with no patch available.

Research by OX Security finds widespread Model Context Protocol servers lacking governance over location, domain ownership, and persistent access, complicating data residency and supply chain oversight for enterprises.

Revolut customers trading US stocks were affected by a data breach at brokerage DriveWealth, exposing personal details from former account records. The incident marks the second breach notification for Revolut users this month.

A recently identified malware strain, Carbonato, is targeting exposed Docker hosts to deploy AI-driven agents, enabling remote control and potential lateral movement within infrastructure.

A critical Roundcube Webmail vulnerability patched in May 2026 is now under active exploitation, with attackers injecting malicious code into unpatched instances.

cPanel released fixes for a privilege-escalation vulnerability that allowed authenticated users to execute code as root. The same researcher also reported critical flaws in Plesk’s Backup Manager during the same period.

Security researchers detail how Google Kubernetes Config Connector permissions may allow privilege escalation from a single Kubernetes user to an entire Google Cloud organization.

Arista Networks released emergency patches for a zero-day vulnerability in VeloCloud Orchestrator On-Prem deployments, which was being actively exploited in the wild.

Master of Malt, a UK-based whisky retailer, disclosed a data breach after attackers compromised a third-party e-commerce app, exposing customer names, addresses, emails, and phone numbers. Payment details remained secure.

A newly disclosed cross-site request forgery vulnerability in WordPress Core, dubbed Click2Shell, lets unauthenticated attackers execute arbitrary PHP code on vulnerable servers. Technical details and a proof-of-concept exploit are now public.

Gyazo disclosed a data breach after attackers exploited a server vulnerability to steal 23.6 million user records, including email addresses and hashed passwords. The company has begun notifying affected users and reset all account credentials.

Brevo disclosed a supply-chain attack where threat actors stole a Cloudflare API key, enabling injection of ClickFix malware scripts into customer websites and embedded JavaScript files. The incident highlights risks of third-party API credential exposure in SaaS platforms.

Microsoft reverted a configuration change after it caused widespread errors in SharePoint Online, leaving users unable to load pages. The incident, tracked as SP1472983, lasted 90 minutes and follows similar recent cloud service disruptions.

The FBI has seized domains linked to NightmareStresser, a DDoS-for-hire platform allegedly responsible for thousands of attacks worldwide. The takedown follows coordinated action by US law enforcement.

A mid-size company discovered a test environment connected to live customer data remained accessible externally for six months, risking a major breach during a routine security audit.

The KB5124008 security update for Windows 11 is preventing some enterprise users from authenticating with domain credentials, Microsoft confirmed on Wednesday.

Cloudflare's Client-Side Security machine learning model identified four distinct malware operations targeting e-commerce storefronts, all bypassing VirusTotal and URLScan. The campaigns hijacked affiliate revenue, sabotaged analytics, and opened remote backdoors without server-side compromise.

Salesforce experienced a global outage on 16 September 2026, affecting hundreds of customer instances across multiple regions. The disruption, caused by an internal login service bottleneck, coincided with the company's annual Dreamforce conference in San Francisco.

Acronis has disclosed a high-severity vulnerability in its cPanel, WHM, and Plesk backup plugin, with evidence of active exploitation on Linux systems.

The U.S. Cybersecurity and Infrastructure Security Agency reports that ransomware gangs are now targeting a critical remote-code-execution vulnerability in VMware vCenter, patched in July 2026.