Blog
PaperCut NG/MF Zero-Day: Attackers Compromise Print Servers in Under Two Minutes — Emergency Patches Released August 28, 2026
A zero-day in PaperCut NG/MF print management software is actively exploited across all versions. Emergency patches released Aug 28 — act before ransomware groups move in.
Read More →Qilin Ransomware Hits the ATF: Russia-Linked Gang Claims Breach of Federal Firearms Agency as ‘Major Incident’ Declared
Qilin ransomware claimed the ATF in August 2026, breaching a standalone system with federal investigation target data. CISA KEV, zero-trust lessons, and what Indian enterprises must do now.
Read More →CVE-2026-77550 (CVSS 10.0): Ubiquiti Patches 21 Critical UniFi Flaws — Three Authentication-Free Exploits Expose Cameras, VoIP, and Network OS to Unauthenticated Takeover
Ubiquiti disclosed 22 critical UniFi vulnerabilities on 26 August 2026, including three CVSS 10.0 flaws. Learn which CVEs to patch first and how to defend your network now.
Read More →CVE-2026-18577 (CVSS 8.2): Hackers Exploit N-able N-central Auth Bypass to Seize MSP Consoles — CISA Issues Patch Deadline
CVE-2026-18577 lets unauthenticated attackers seize N-able N-central RMM consoles and all managed endpoints. CISA KEV added August 3, 2026. Patch to 2026.3.1.10 immediately.
Read More →CVE-2026-21962 (CVSS 10.0): Oracle WebLogic Proxy Flaw Fuels 140,000 Attacks — China-Linked APT Strikes 100+ Governments, CISA 72-Hour Deadline
CVE-2026-21962 (CVSS 10.0) in Oracle HTTP Server and WebLogic Proxy Plug-in enables unauthenticated RCE. CISA KEV-listed with 72-hour patch deadline as China-linked APT exploits 100+ governments.
Read More →CVE-2026-59310 (CVSS 9.8): Chinese APT Exploits VMware vCenter in 5 Days — 361 Victims, Babuk Ransomware Encrypts ESXi
CVE-2026-59310 (CVSS 9.8) lets unauthenticated attackers gain root RCE on VMware vCenter via Syslog path traversal. 361 victims in 47 countries; Babuk ransomware deployed on ESXi. Patch VMSA-2026-0006 immediately.
Read More →CVE-2026-58231 (CVSS 10.0): Attackers Exploit SAP Commerce Cloud in 72 Hours — 4,200+ Shops Exposed, Patch Now
CVE-2026-58231 is a CVSS 10.0 RCE in SAP Commerce Cloud exploited just 72 hours after patching. 4,200+ instances exposed — patch via SAP Note 3771065 now.
Read More →CVE-2026-65400 (CVSS 9.8): Attackers Are Silently Rooting Macs via Screen Sharing — 40,000 Hosts Exposed, Monero Miners Deployed
CVE-2026-65400 lets network attackers bypass macOS Screen Sharing auth and gain root without credentials. 40,000 hosts exposed, XMRig Monero miner deployed. CISA CVSS 9.8. Patch now.
Read More →Gunra RaaS: Six Intelligence Agencies Issue Emergency Alert as Conti’s Heir Exploits FortiGate Vulnerabilities — 51 Victims, $10M+ Ransom Demands
CISA, FBI & four partner agencies warn of Gunra ransomware exploiting FortiOS CVE-2024-55591 (CVSS 9.8) to hit healthcare, govt & critical infrastructure globally.
Read More →iAuthFlow v2 & Pass-the-Passkey (CVE-2026-34348): The $10,000 Attack Turning Your Passkeys Against You
A $10,000 underground phishing kit dubbed iAuthFlow v2 enrolls attacker-controlled passkeys in ~6 seconds, persisting through password resets — while CVE-2026-34348 exposed YubiKey signatures stored in cleartext Windows Event Logs.…
Read More →