Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The AhnLab SEcurity intelligence Center (ASEC) recently identified the LegionLoader malware, which is currently being distributed via the ClickFix method. There are two main distribution methods identified so far; both involve tricking users into visiting a malicious URL and then prompting them to directly execute malicious PowerShell commands through a fake Cloudflare CAPTCHA screen.
1. Overview The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments.
This article describes CVE-2026-82329, a critical authentication bypass vulnerability in JFrog Artifactory that allows unauthenticated attackers to gain admin privileges. The flaw is actively exploited, enabling token generation and enumeration of sensitive data.
HPE has released security updates addressing a maximum-severity remote code execution vulnerability affecting its network fabric management platform. Tracked as CVE-2026-76658 and rated 10.0 on the CVSS v3.1 scale, the flaw can allow an unauthenticated remote attacker to gain administrative access and execute arbitrary commands as a privileged operating-system user.
This article describes active attacks exploiting two zero-day vulnerabilities in PaperCut NG and MF print management platforms. CVE-2026-81578 is an authentication bypass that, when chained with CVE-2026-82078, enables unauthenticated remote code execution.
Manifold Security discovered eight security flaws in seven command-line AI coding agents, including Claude, Codex, and Cursor, where a malicious .git configuration can execute attacker code on the developer's machine. The vulnerability exploits Git's core.fsmonitor setting, which runs a command when the agent performs background operations like git status or git diff.