The Cybersecurity and Infrastructure Security Agency (CISA) added several vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after confirming they are being exploited in the wild. The vulnerabilities include CVE-2026-65400 (Apple macOS), CVE-2026-55040 (Microsoft SharePoint), CVE-2026-59310 (Broadcom VMware vCenter), CVE-2026-33824 (Microsoft IKE Service Extensions), and CVE-2026-64849 (MLflow). The flaws could allow attackers to bypass authentication, access systems, or execute arbitrary code remotely.
Another two flaws that have come under active exploitation are the GeoServer SQL injection flaw that can lead to remote code execution, and the SAP Commerce Cloud (CVE-2026-58231) RCE issue.
The CERT Polska says that threat actors are actively exploiting an OS command injection flaw in Zimbra Collaboration Suite. The vulnerability (CVE-2026-73570) allows an unauthenticated attacker to execute arbitrary shell commands with the privileges of the zimbra user. The issue impacts instances that have the SNMP trap service enabled via the snmp_notify parameter and the swatchdog service running (enabled by default). The vulnerability was fixed in version 10.1.20. The team didn’t provide any additional details on the nature of the exploitation of CVE-2026-73570.
Microsoft has disclosed a high-severity Entra ID vulnerability (CVE-2026-69836) that has been exploited in attacks. The flaw could allow attackers with no privileges to execute code. Microsoft says exploit code is not publicly available and no user action is needed because the vulnerability has already been patched. The vendor has not provided further details.
Citrix has warned users to patch NetScaler Gateway and NetScaler ADC systems against two vulnerabilities as soon as possible. One of the flaws (CVE-2026-19490) could let unauthenticated remote attackers bypass authentication on affected systems, depending on the firmware version and configuration. The second one (CVE-2026-19489) can be exploited to trigger denial-of-service.
The US authorities issued a security advisory warning of attacks targeting critical infrastructure, more specifically, vulnerable PLC systems, especially Siemens S7 devices. Threat actors are using AI-generated scripts to find internet-exposed systems with outdated or weak security. The activity affects sectors such as energy, water, manufacturing, chemicals, and agriculture. The authorities didn’t attribute the observed activity to any particular threat actor.
A custom Java web shell linked to the Clop ransomware gang has been used to target PTC Windchill and FlexPLM servers. The web shell was found after attackers exploited CVE-2026-12569, a critical remote code execution flaw in PTC Windchill. The malware can connect to Windchill databases, decrypt stored credentials, search file repositories and steal files. It also uses a custom X-windchill-req HTTP header to receive commands.
Three suspected Russian cyber-espionage groups, tracked as UNC6293, UNC7005, and UNC5976, are targeting people in academia, government, defense, aerospace, and think tanks in Europe and the US. The groups mainly use phishing and legitimate authentication methods, such as OAuth and device-code phishing, to steal account access and tokens. UNC6293 and UNC7005 are linked to the Russian Ice Relic/APT29 group; UNC7005 has focused on academics, diplomats, and nonprofits. UNC5976 has also targeted aerospace-related organizations, including a possible Ukrainian target.
ThreatFabric has discovered a new Android malware called Manic that combines banking fraud with spyware and remote device control. It mainly targets users and services in Ukraine, including banks, government services, identity apps, and messaging platforms, while also targeting financial and cryptocurrency services in Russia and Europe. Manic can monitor and control infected devices and uses an unusual Wi-Fi mesh system to send data through other infected phones that have internet access.
More than 14,000 Dahua IP cameras were compromised in a multi-stage cyber campaign that mainly affected networks in Ukraine and Russia. The attacks leveraged several techniques, including automated password guessing against exposed cameras; vulnerabilities or authentication bypasses that allowed the attacker to access device functions without the normal login process; and Dahua's P2P relay service, which can provide remote access through the manufacturer's cloud infrastructure.
In an unrelated incident, Slovakia’s national security service (NBU) has warned about a potential backdoor in NERO R-ONE traffic cameras, which could allow malicious code to be sent via SMS from Russian phone numbers.
Recorded Future’s Insikt Group has spotted multiple clusters of North Korean IT workers, known as PurpleDelta, likely operating from China that used fake identities, AI-generated profiles, and stolen or fake documents to apply for jobs at more than 1,100 companies, with some securing employment at at least 10 organizations. They operated at a high pace, sometimes submitting 60+ job applications per day while managing multiple fake identities. They also used AI during interviews, recorded workplace meetings, and coordinated with facilitators through platforms such as Telegram and Slack.
A China-nexus threat actor has launched a campaign, tracked as ‘Operation QUICSILVER,’ targeting Myanmar government personnel with a custom Go-based backdoor delivered via a Virtual Hard Disk (VHD) file. QUICAgent collects basic system information and sends it in an initial beacon. It supports five operator commands, including command execution, file transfer, directory browsing, and control of the beacon interval. The malware discovers its command-and-control (C&C) server via Cloudflare Workers and communicates over HTTP/3 using the QUIC protocol.
Cybersecurity firm Huntress has detailed an attack where an Akira ransomware affiliate disabled security tools on a compromised system by restarting it into Windows Safe Mode with Networking. The intruder gained access via an exposed SonicWall VPN without multi-factor authentication (MFA), and then accessed the domain controller through RDP, searched for users and computers, and moved to an application server.
Zscaler ThreatLabz came across a new Rust-based malware family called C2Looper, likely linked to a ransomware-related threat actor. It can execute commands, gather system information, and deploy additional malware. C2Looper is still under active development, with newer variants adding features such as GitHub-based command-and-control. ThreatLabz assesses with low to medium confidence that it may be distributed through ClickFix infection campaigns.
A previously undocumented espionage group called SilkParasite has been targeting government organizations across Central Asia. The group, first spotted in late 2025, is believed to have links to China. Its attacks use seven remote access tools, including five malware families (DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT) that had not been publicly documented before.
Ontinue’s Cyber Defense Center has uncovered a previously undocumented Python malware framework used in an ongoing campaign investigated in July 2026. Tracked as TWINLOOT, the malware is a modular Python implant protected with PyArmor 9.2.5 Pro that keeps its C&C infrastructure inside trusted Microsoft services like SharePoint Online, Microsoft Graph API and Microsoft Teams TURN servers.
Cisco Talos discovered a phishing framework called JWR that creates fake checkout and login pages to steal sensitive information. It allows attackers to control victims’ sessions in real time and collect payment details, passwords, 2FA codes, identity documents, and device information. Talos believes JWR may be a version of another phishing service called The Outsider. The framework has been used in SMS scams pretending to be toll, postal, and courier services in Southeast Asia and the Middle East.
Rapid7 researchers uncovered a cryptocurrency fraud operation, called Operation ASTERIX, that leverages phishing, phone calls, fake crypto wallets, and automated tools. The operators also used AI coding assistants to build, obfuscate, troubleshoot, and distribute the malware and phishing tools. When an AI model resisted certain requests, the operator switched models and tried to bypass its safety controls.
Researchers at the University of Massachusetts Amherst found a way to make some expired Visa contactless cards work again. The technique named Zombie Card changes the expiration date read by a payment terminal without breaking the card’s security. The attack requires physical access or close NFC proximity to the card, a man-in-the-middle device, and an account that is still active. It also depends on the bank not checking the expiration date again during payment authorization.
Former IT contractor Cameron Curry was sentenced to two years in prison for stealing company data and attempting to extort $2.5 million in cryptocurrency. The company paid him $7,540 before reporting the incident to the FBI.
German and Brazilian authorities arrested four suspects linked to the theft of more than €30 million from German bank customers. The attackers exploited a software vulnerability, moved the stolen money to Brazil and Europe, and allegedly used companies and crypto platforms to launder it.
Israeli police arrested a man suspected of installing malware on computers at dozens of companies and stealing sensitive information. Authorities believe he acted alone; his motive and the full scale of the alleged theft remain unclear.
US authorities charged 17 Iranians over an alleged cybertheft campaign targeting universities, government agencies and companies. Prosecutors say the group stole at least 31.5 terabytes of academic research and intellectual property and compromised thousands of university accounts. In addition, the US State Department is offering up to $10 million for information that could help locate five of the Iranian defendants.