Blog
CVE-2026-34486 (CVSS 7.5): Apache Tomcat’s Broken Cluster Patch Enables Unauthenticated RCE — CISA Adds to KEV as SNOWLIGHT Campaign Hits 100+ Countries
CISA adds CVE-2026-34486 to KEV as China-linked attackers exploit a broken Apache Tomcat cluster patch to deliver SNOWLIGHT malware across 100+ countries.
Read More →CVE-2026-9198 (CVSS 9.8): Hackers Are Using Two API Calls to Own Your AI Infrastructure — Langflow Hits CISA’s Must-Patch List
CISA flags CVE-2026-9198 (CVSS 9.8): Langflow AI platform exploited via two unauthenticated API calls. Patch to v1.10.1 before August 7 deadline.
Read More →CaptiveCrunch: Russia’s Midnight Blizzard Is Hijacking Hotel Wi-Fi to Steal Your Microsoft 365 Credentials
Russia's Midnight Blizzard (APT29) is hijacking hotel Wi-Fi via the CaptiveCrunch campaign, deploying CornFlake RAT and ChocoShell to steal Microsoft 365 tokens from corporate travellers worldwide.
Read More →CVE-2026-45321: Mini Shai-Hulud npm Worm Poisons 420 Packages and 2 Billion Monthly Installs — Claude Code and VS Code Weaponised as Persistence Hooks
The Mini Shai-Hulud npm worm compromised 420+ packages and 2B monthly installs on Aug 4. Learn how it spread, what credentials it stole, and how to remove it safely.
Read More →CVE-2026-15409 (CVSS 10.0): INC Ransomware Chains SonicWall SMA1000 Zero-Days to Hijack VPN Infrastructure — 885 Victims and Counting
INC Ransomware weaponises CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in SonicWall SMA1000 appliances. Patch to 12.4.3-03453 now — 885 victims listed globally.
Read More →CVE-2026-18556 & CVE-2026-18577: N-able N-Central’s Failed Patch Left MSP Networks Open to God-Mode Takeover — Act Now
N-able N-central's incomplete patch for CVE-2026-18556 led to CVE-2026-18577; attackers gained unauthenticated RMM admin access and planted persistent Cloudflare tunnels. Patch to 2026.3.1.7 immediately.
Read More →Microsoft Teams Is Now a Ransomware Entry Point: STAC4749 Deploys Chaos in Under 17 Hours
Sophos tracked STAC4749, a Conti-lineage ransomware campaign that impersonates IT helpdesk via Microsoft Teams to deploy Chaos ransomware in under 17 hours. Learn how to defend your organisation.
Read More →Microsoft Teams Is Now a Ransomware Entry Point: STAC4749 Deploys Chaos in Under 17 Hours
Sophos tracked STAC4749, a Conti-lineage ransomware campaign that impersonates IT helpdesk via Microsoft Teams to deploy Chaos ransomware in under 17 hours. Learn how to defend your organisation.
Read More →CVE-2026-66066 (CVSS 9.5): KindaRails2Shell — Any Rails Image Upload Can Expose Your Master Key and Hand Attackers Full RCE
CVE-2026-66066 (CVSS 9.5) lets unauthenticated attackers upload a crafted file to read arbitrary Rails server files — including the secret_key_base — and escalate to full remote code execution.
Read More →Iran-Linked CyberAv3ngers Hit 30+ US Water Systems With an Unpatchable PLC Flaw — Boil-Water Notices Issued, 7 States on Alert
Iran-linked CyberAv3ngers exploited unpatchable CVE-2021-22681 in Rockwell Allen-Bradley PLCs to disrupt 30+ Minnesota water utilities. CISA issues urgent disconnect order as 7 US states report incidents.
Read More →