Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update.
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks.
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, according to a cPanel advisory published on September 14, 2026. The flaw affects versions before a specific patch release, and LiteSpeed has published a security update addressing the issue.
Cisco has warned that a critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway (CVE-2026-76461, CVSS 9.8) has come under active exploitation in the wild. The insufficient email parsing validation allows unauthenticated remote attackers to execute arbitrary commands with root privileges.
A Chinese threat actor tracked as UTA0560 has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. The campaign targeted multiple non-governmental organizations on September 1, 2026, using emails that encouraged users to click a link leading to a compromised U.S.-based website. Volexity identified the activity and attributed it to Chinese state-sponsored hacking operations.
PhantomRaven is an LLM-generated information stealer developed specifically for bug bounty hunting. The tool leverages large language models to create malware capable of exfiltrating sensitive data from compromised systems.