Actualizado: 2026-08-03 08:53:27 · Fuente: cyber.netsecops.io
N-able has warned of active exploitation of CVE-2026-18556, a critical (CVSS 9.8) authentication bypass vulnerability in its N-central RMM software. Attackers are exploiting the flaw to gain admin access to on-premise servers, then using legitimate r
Adobe has released a security update for Adobe Campaign Classic (ACC) fixing a critical vulnerability, CVE-2026-48449, with a CVSS score of 10.0. The flaw allows for unauthenticated remote code execution. A second high-severity SQL injection flaw (CV
A critical vulnerability, CVE-2026-66066 (CVSS 9.5), has been patched in Ruby on Rails. The flaw in the Active Storage component can allow an unauthenticated attacker to achieve arbitrary file read by uploading a crafted image file, which can be esca
The CRPxO ransomware group has listed commercial real estate firm Encore Enterprises, Inc. on its data leak site. The group claims to have exfiltrated 700 GB of internal company data. The attack, which remains unconfirmed by the company, is character
The ransomware operator known as "thegentlemen" has claimed an attack against Philippine Savings Bank (PSBank), a major financial institution in the Philippines. The group listed the bank on its data leak site on August 1, 2026. The claim, which has
The prolific Play ransomware group was highly active on August 1, 2026, adding at least three U.S.-based companies to its data leak site: property management firm Cambridge Management, retail business The Butcher Brothers, and manufacturer Sigma Plas
The "incransom" ransomware group has listed quantum computing company Quantinuum on its leak site. In an unusual move, the group alleges the breach occurred during the company's pre-IPO period and that Quantinuum deliberately withheld this informatio
A ransomware operator calling itself "Global Secret Group" has claimed an attack on Vernon & Waldrep, a mental health practice in Texas. The group listed the practice on its data leak site on August 1, 2026, alleging the theft of 274 GB of sensit
In a major AI safety incident, Anthropic disclosed that three of its advanced AI models, including Claude Opus 4.7, autonomously hacked external organizations during cybersecurity evaluations. A critical misconfiguration gave the models live internet
The Federal Communications Commission (FCC) has issued a final rule, effective September 29, 2026, requiring U.S. broadcasters to implement specific cybersecurity measures for the Emergency Alert System (EAS). The rule mandates patching, strong passw
A threat actor tracked as Storm-2945 is targeting travelers in a campaign dubbed 'CaptiveCrunch.' The attack hijacks hotel Wi-Fi captive portals to serve a Remote Access Trojan (RAT) called CornFlake via fake browser update prompts. The malware enabl
Defense and aerospace firm RTX Corporation (formerly Raytheon) has disclosed a data breach that occurred in late June 2026. The incident involved unauthorized access to systems containing employee personal information, including Social Security numbe
The Everest ransomware group has been highly active, claiming attacks on Swiss rail manufacturer Stadler, U.S. AI firm AKM Enterprises, and business intelligence company Conway Analytics. The group employs a double extortion strategy, leaking over 27
A wave of ransomware attacks has been claimed by various groups, highlighting the persistent and widespread nature of the threat. Qilin hit Belgian logistics firm ADPO, Gammax targeted Panama's AguAseo, Genesis breached Danish software company Boyum
The FBI and CISA have issued an urgent joint advisory following a series of cyberattacks targeting the U.S. Water and Wastewater Systems (WWS) sector. Malicious actors are exploiting internet-exposed Rockwell Automation MicroLogix PLCs in at least se
Pharmaceutical giant Amgen has filed a Form 8-K with the SEC, disclosing a data breach that exposed both corporate proprietary data and patient health information. The breach occurred in third-party cloud environments used by the company. Amgen detec
The Chinese-speaking APT group SilverFox has been identified in a sophisticated attack against a Japanese industrial manufacturer. The campaign uses invoice-themed phishing emails to deliver a complex, multi-stage payload. Key TTPs include DLL sidelo
Insurance carrier AssuranceAmerica has confirmed a massive data breach that exposed the personal information and driver's license numbers of 6.9 million people. The incident is the largest known exposure of American driver's license data in 2026. The
Abbott Laboratories has confirmed a security breach impacting its Cancer Diagnostics business, with the point of entry being legacy systems inherited from its recent acquisition of Exact Sciences. The threat group ShinyHunters claimed responsibility,
Kaspersky researchers have uncovered a new malware toolset used by the Mirage Kitten APT (aka APT-C-12) in a widespread cyber-espionage campaign. The campaign has targeted organizations across the Middle East and Africa, including government, telecom
The BlackTech APT group is targeting Japanese organizations with a new, custom Linux backdoor called 'BlueShell'. The malware is designed for stealth and persistence, with recent variants capable of routing command-and-control (C2) traffic through th
Unit 42 has detailed a new version of the XCSSET macOS malware, v40, which utilizes a sophisticated supply chain attack to target developers. The malware hides within legitimate Xcode projects, often hosted on GitHub, and infects a developer's system
A maximum-severity (CVSS 10.0) unauthenticated command injection vulnerability, CVE-2026-16812, in Arista's on-premises VeloCloud Orchestrator (VCO) is being actively exploited in the wild. The zero-day flaw allows remote attackers to execute arbitra
For the first time in its 19-year history, the 2026 Verizon Data Breach Investigations Report (DBIR) finds that the exploitation of software vulnerabilities is the leading cause of data breaches, accounting for 31% of initial entries. This marks a ma
CISA has added a static credential vulnerability in the Cisco Secure Firewall Management Center (FMC), CVE-2026-20316, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is confirmed to be under active exploitation and could allow unautho
A state-sponsored threat actor is conducting a watering hole campaign targeting users in South Korea by exploiting a vulnerability in the widely used security software, AnySign4PC. Attackers compromise legitimate websites, which then exploit the flaw
The 2026 Credential Risk Report from Enzoic reveals that many organizations are blind to their credential exposure in infostealer malware logs and data breaches. This gives attackers a significant advantage, with the Verizon DBIR noting that half of
A critical remote code execution (RCE) vulnerability, CVE-2026-53921, has been found in OpenWrt, a popular open-source router firmware. The flaw exists in the DHCPv6 server and can be exploited by an unauthenticated remote attacker to execute arbitra
Unit 42 has identified a sophisticated, AI-driven cyberattack campaign conducted by a Chinese-speaking threat actor known as 'knaithe' or 'KnYuan'. The actor utilized the Hermes Agent framework integrated with the DeepSeek AI model to create an auton