
Kiteworks orders global 6-hour server shutdown over zero-day threat
Kiteworks instructed all customers to shut down servers for six hours on Saturday after receiving threat intelligence about a potential zero-day attack, with no patch available.

Kiteworks instructed all customers to shut down servers for six hours on Saturday after receiving threat intelligence about a potential zero-day attack, with no patch available.

Research by OX Security finds widespread Model Context Protocol servers lacking governance over location, domain ownership, and persistent access, complicating data residency and supply chain oversight for enterprises.

A recently identified malware strain, Carbonato, is targeting exposed Docker hosts to deploy AI-driven agents, enabling remote control and potential lateral movement within infrastructure.

A critical Roundcube Webmail vulnerability patched in May 2026 is now under active exploitation, with attackers injecting malicious code into unpatched instances.

cPanel released fixes for a privilege-escalation vulnerability that allowed authenticated users to execute code as root. The same researcher also reported critical flaws in Plesk’s Backup Manager during the same period.

Security researchers detail how Google Kubernetes Config Connector permissions may allow privilege escalation from a single Kubernetes user to an entire Google Cloud organization.

Arista Networks released emergency patches for a zero-day vulnerability in VeloCloud Orchestrator On-Prem deployments, which was being actively exploited in the wild.

A newly disclosed cross-site request forgery vulnerability in WordPress Core, dubbed Click2Shell, lets unauthenticated attackers execute arbitrary PHP code on vulnerable servers. Technical details and a proof-of-concept exploit are now public.

A mid-size company discovered a test environment connected to live customer data remained accessible externally for six months, risking a major breach during a routine security audit.

The KB5124008 security update for Windows 11 is preventing some enterprise users from authenticating with domain credentials, Microsoft confirmed on Wednesday.

Acronis has disclosed a high-severity vulnerability in its cPanel, WHM, and Plesk backup plugin, with evidence of active exploitation on Linux systems.

The U.S. Cybersecurity and Infrastructure Security Agency reports that ransomware gangs are now targeting a critical remote-code-execution vulnerability in VMware vCenter, patched in July 2026.

The Dutch National Cyber Security Centre has issued an alert about two critical vulnerabilities in Check Point VPN products, warning that exploitation is expected shortly.

GitLab has urged users to apply an immediate patch for a critical path traversal vulnerability affecting its self-managed instances, warning of potential unauthorized access risks.

WHMCS released fixes for a critical remote code execution vulnerability (CVE-2026-67399) and a separate data-exposure flaw in its billing and automation platform. Administrators must upgrade to 9.0.8 or 8.13.7 to mitigate risks.

Cisco has acknowledged that attackers are actively exploiting a critical authentication bypass vulnerability in Secure Firewall Management Center, tracked as CVE-2026-20079.

G7 cybersecurity agencies have issued a call to action for governments and businesses to begin immediate planning for post-quantum cryptography migration, citing risks to authentication, DNSSEC, TLS, and routing security. The transition is expected to take years and requires coordinated action across digital infrastructure.

Adobe released an emergency security update on Tuesday to address CVE-2026-75650, a max-severity zero-day vulnerability in Magento and Adobe Commerce actively exploited to install backdoors on e-commerce servers. The flaw, dubbed StyleSmuggler, was under active attack prior to patching.

Hosting providers and merchants face active exploitation of a Magento zero-day (StyleSmuggler) that bypasses all current patches. The first confirmed victim ran the latest security updates, and Adobe has yet to release a fix or CVE. Mitigation requires disabling GraphQL or deploying third-party blocking tools.

Attackers are exploiting two recently disclosed RouterOS flaws to compromise MikroTik routers with internet-exposed SSH services, security researchers report.