Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Russian threat actors are exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Outlook Web Access, to target U.S. and European government entities as well as telecommunications, financial, hospitality, and aerospace sectors. The activity, attributed to Laundry Bear, involves sending emails from compromised accounts that trigger the exploit and allow persistent mailbox access.
Russian threat actors tracked as Laundry Bear (Void Blizzard, TA488) exploited CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Outlook Web Access (OWA), to maintain mailbox access even after credential rotation. The campaign, active since July 22, 2026, targets U.S. and European government entities and the telecommunications, financial, hospitality, and aerospace sectors.
The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, generally preventing new models from receiving equipment authorization for import, marketing, or sale in the US. Previously authorized models and devices already owned are unaffected. The FCC's Office of Engineering and Technology granted a waiver through January 2029 for software/firmware security updates.
The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, generally preventing new models from receiving equipment authorization for import, marketing, or sale in the US. Previously authorized models and devices already owned are unaffected. The FCC's Office of Engineering and Technology granted a waiver through January 2029 for software/firmware security updates.
The FCC has added foreign-produced mobile robots and networked power inverters to its Covered List, blocking new models from import and sale. The move aims to mitigate cyber risks, but existing devices and previously authorized hardware are unaffected.
Amazon's threat intelligence team attributed the September 2025 hijack of npm packages debug and chalk to North Korea's Sapphire Sleet group. The attribution is based on shared tradecraft, code reuse, and command-and-control overlaps across three campaigns over twelve months.