Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article from Heimdal Security analyzes new malware threats, detailing their infection vectors, capabilities, and indicators of compromise. Understanding these threats helps organizations strengthen their defensive posture against evolving malicious software.
This Dark Reading article reports on a newly discovered authentication bypass vulnerability, CVE-2026-18577, in N-able's N-central platform. Attackers are exploiting this flaw to gain administrator access to the remote monitoring and management servers.
This Sophos Threat Research article describes how threat actors exploit CVE-2026-18577 to compromise N-able N-central servers. After gaining access, they deploy additional remote monitoring and management tools and establish network tunnels.
Cisco has disclosed an actively exploited high-severity vulnerability in ASA and FTD software. The flaw, CVE-2026-20349, allows an unauthenticated attacker to trigger a denial-of-service through crafted HTTP requests to the Remote Access SSL VPN service.
Attackers are exploiting a recently patched directory-traversal vulnerability in Broadcom VMware vCenter to execute arbitrary code. They establish persistence using malicious cron jobs and reverse_ssh, with over 360 victims across 47 countries.