Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article describes a supply chain attack where a trojanized version of the QuickFox VPN installer delivered the FDMTP backdoor, linked to Mustang Panda. The attack targeted Windows users and remained active from August 2025 until a fix was released in version 3.59.6.
Multiple vulnerabilities were identified in Apache Tomcat that could allow a remote attacker to bypass security restrictions, disclose sensitive information, and manipulate data. CVE-2026-34486 is being actively exploited in the wild.
This article warns of multiple vulnerabilities in TP-Link Omada products that could be exploited to compromise network management systems. TP-Link has released firmware updates, and the analyst recommends immediate patching and network access restrictions.
A vulnerability in Mozilla Firefox for Android allows address bar spoofing, potentially leading to phishing attacks. Mozilla has released version 153.0.3 to fix the issue.
Over the last six months, we have been engaging closely with the European Commission (EC) after they opened specification proceedings related to Android interoperability…
Microsoft Security analyzes the ChainDrop supply chain compromise, a self-propagating worm. The article outlines the attack chain, mitigation steps, and indicators of compromise.