Blog
CVE-2026-12569 (CVSS 9.3): Cl0p’s Custom Web Shell Is Draining Engineering Blueprints from 40+ Global Manufacturers
Cl0p ransomware's custom JSP web shell exploits CVE-2026-12569 (CVSS 9.3) to silently drain engineering data from PTC Windchill and FlexPLM — 40+ victims named including Shell, Philips, and GE. Patch…
Read More →CVE-2026-33824 (CVSS 9.8): Chinese APT Uses DeepSeek AI to Autonomously Attack 460+ Windows IKE VPN Endpoints — CISA KEV Patch Deadline Passed
A Chinese-speaking threat actor used DeepSeek AI and the Hermes Agent framework to autonomously exploit CVE-2026-33824, a CVSS 9.8 pre-auth RCE in Windows IKE. Over 460 targets hit; CISA KEV…
Read More →CVE-2026-8452 (CVSS 9.8): Citrix NetScaler’s “DoS-Only” Patch Is Pre-Auth Root RCE — CISA Deadline Passed, Webshells Deployed on 22,000+ Exposed Appliances
CVE-2026-8452 (CVSS 9.8) in Citrix NetScaler enables pre-auth root RCE via heap buffer overflow. CISA’s federal deadline passed Aug 29—patch to 14.1-73.32+ or 13.1-63.21+ immediately.
Read More →CVE-2026-68820 (CVSS 7.0): Lazarus Group’s Operation Dream Job Plants Kernel Rootkit in Indian Defence Firms
Lazarus Group exploited Windows zero-day CVE-2026-68820 (CVSS 7.0) via fake job offers, deploying FudModule 3.1 rootkit in Indian defence firms. Patch now.
Read More →CVE-2026-73570 (CVSS 8.9): Zimbra Mail Servers Under Mass Attack — 274 Servers Compromised as CISA Issues Emergency Patch Deadline
CVE-2026-73570 is an unauthenticated RCE in Zimbra’s SNMP monitoring component, actively exploited in the wild. 274 servers compromised in days. CISA added to KEV August 21. Patch ZCS 10.1.20 now.
Read More →PaperCut NG/MF Zero-Day: Attackers Compromise Print Servers in Under Two Minutes — Emergency Patches Released August 28, 2026
A zero-day in PaperCut NG/MF print management software is actively exploited across all versions. Emergency patches released Aug 28 — act before ransomware groups move in.
Read More →Qilin Ransomware Hits the ATF: Russia-Linked Gang Claims Breach of Federal Firearms Agency as ‘Major Incident’ Declared
Qilin ransomware claimed the ATF in August 2026, breaching a standalone system with federal investigation target data. CISA KEV, zero-trust lessons, and what Indian enterprises must do now.
Read More →CVE-2026-77550 (CVSS 10.0): Ubiquiti Patches 21 Critical UniFi Flaws — Three Authentication-Free Exploits Expose Cameras, VoIP, and Network OS to Unauthenticated Takeover
Ubiquiti disclosed 22 critical UniFi vulnerabilities on 26 August 2026, including three CVSS 10.0 flaws. Learn which CVEs to patch first and how to defend your network now.
Read More →CVE-2026-18577 (CVSS 8.2): Hackers Exploit N-able N-central Auth Bypass to Seize MSP Consoles — CISA Issues Patch Deadline
CVE-2026-18577 lets unauthenticated attackers seize N-able N-central RMM consoles and all managed endpoints. CISA KEV added August 3, 2026. Patch to 2026.3.1.10 immediately.
Read More →CVE-2026-21962 (CVSS 10.0): Oracle WebLogic Proxy Flaw Fuels 140,000 Attacks — China-Linked APT Strikes 100+ Governments, CISA 72-Hour Deadline
CVE-2026-21962 (CVSS 10.0) in Oracle HTTP Server and WebLogic Proxy Plug-in enables unauthenticated RCE. CISA KEV-listed with 72-hour patch deadline as China-linked APT exploits 100+ governments.
Read More →