(Adobe Stock) CISA: WatchGuard Firebox bug exploited in ransomware campaignsSteve ZurierSeptember 10, 2026Ransomware gangs are exploiting a WatchGuard Firebox flaw that CISA flagged nine months ago.
One report, many missions: A better way to coordinate America’s cyber defenseCory SimpsonSeptember 9, 2026
Over 36,000 Plex media servers remain unpatched against security vulnerabilitiesSC StaffSeptember 9, 2026
Closing the accountability divide: How to prove what happened in a breachPaul WagenseilSeptember 8, 2026
AI/MLPaperCut MF/NG flaws attacked with hundreds of AI agentsLaura FrenchSeptember 10, 2026The AI-assisted campaign enabled attackers to gain domain admin in as little as 5 minutes.
Network SecurityF5 BIG-IP malware hides web shells in memory to evade detectionSteve ZurierSeptember 9, 2026Memory-resident malware targeting F5 BIG-IP appliances can evade file-based security defenses.
IdentityBigBear 2.0 phishing campaign compromises MFA-protected Microsoft accountsLaura FrenchSeptember 9, 2026Researchers discovered more than 3,300 unique victims across 461 organizations.
Vulnerability ManagementN-able patches critical N-central RCE flaw amid exploit concernsSteve ZurierSeptember 8, 2026N-able patched a critical N-central RCE flaw amid concerns about potential active exploitation.
Email securityASCII smuggling challenges email phishing filters, Microsoft warnsLaura FrenchSeptember 4, 2026Invisible Unicode tag characters often used for AI prompt injection have appeared in high-volume phishing attacks.
Network SecurityHPE patches ArubaOS-CX switches vulnerable to remote code executionSteve ZurierSeptember 4, 2026HPE patched 35 ArubaOS-CX flaws, including a critical bug that could enable remote code execution.
Email security‘Empty envelope’ email attacks target company leadersLaura FrenchSeptember 4, 2026The technique bypasses RejectDirectSend by SMTP envelope sender blank.
PhishingPhishing campaign targets widely used RMM platforms in 46 countriesSteve ZurierSeptember 3, 2026Phishing attacks trick victims into installing legitimate RMM tools for remote access.