Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Critical SNMP Command Injection and XSS Vulnerabilities Found in Zimbra Servers A critical vulnerability in the Simple Network Management Protocol (SNMP) used by millions of email servers worldwide has been discovered, putting user data at risk of exploitation. The flaw, along with four related cross-site scripting (XSS) vulnerabilities, affects all versions of the popular open-source … Read more

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

A sophisticated group of attackers known as Qilin has been exploiting a previously unknown vulnerability in Palo Alto Networks’ (PAN-OS) authentication system, granting them initial access into organizations’ networks and allowing them to deploy ransomware payloads. The attack vector, which leverages an authentication bypass flaw, has left numerous businesses scrambling to assess the scope of … Read more

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Critical SharePoint RCE Flaw Under Active Exploitation After Public PoC A high-severity vulnerability in Microsoft’s SharePoint platform, identified as CVE-2026-50522, is being actively exploited by attackers after a proof-of-concept (PoC) exploit was publicly disclosed online. This remote code execution (RCE) flaw allows unauthenticated attackers to execute arbitrary code on vulnerable systems, potentially leading to data … Read more

25 Years After Code Red: What the Worm Era Can Teach Us About AI Security

Twenty-five years ago, the Code Red worm brought chaos to organizations worldwide, exploiting vulnerable Microsoft IIS servers and spreading rapidly across the internet. This pivotal moment in cybersecurity history exposed a harsh reality that remains true today: organizations cannot secure what they do not know they have. The worm’s impact on modern security practices is … Read more

Microsoft shares manual fix for WSUS sync delays and timeouts

**Microsoft Shares Manual Fix for WSUS Sync Delays and Timeouts, Affects Thousands of Organizations** A critical issue affecting Windows Server Update Services (WSUS) servers has been causing headaches for IT administrators worldwide. Microsoft has acknowledged the problem and shared manual mitigations to help affected organizations fix their WSUS servers and deploy the latest Windows updates. … Read more

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

Critical Palo Alto VPN Bug Exploited by Qilin Ransomware Gang, Puts Thousands at Risk A severe vulnerability in Palo Alto Networks’ GlobalProtect Virtual Private Network (VPN) software has been exploited by the notorious Qilin ransomware gang to breach victims’ networks. The flaw, known as CVE-2026-0257, was patched by Palo Alto on May 13, but it … Read more

US seizes over 1,000 websites in FIFA World Cup piracy crackdown

As the world’s eyes are fixed on the FIFA World Cup, a different kind of battle is unfolding behind the scenes. The US Justice Department has launched a massive crackdown on piracy, seizing over 1,000 websites and blocking nearly 2,000 domains used to stream World Cup matches without authorization. The operation, dubbed “Operation Offsides,” is … Read more

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

WordPress wp2shell Exploit Spreads Rampantly as Public Exploit Code Fuels Widespread Scanning A growing number of WordPress sites have fallen prey to the notorious wp2shell exploit, with a publicly available attack code amplifying the threat. The vulnerability, which stems from an out-of-date plugin and can be exploited using AI-driven scanning tools, has left many website … Read more

Microsoft shares manual fix for WSUS sync delays and timeouts

A major issue affecting Windows Server Update Services (WSUS) servers has prompted Microsoft to share manual mitigations for IT administrators. A known problem with WSUS synchronization is causing Windows Update scans to fail or time out, leaving organizations unable to deploy the latest security patches and updates. The affected platforms include both client-side (Windows 10, … Read more

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

A Critical Palo Alto VPN Bug is Being Exploited by Ransomware Gangs, Putting Thousands at Risk A critical vulnerability in Palo Alto Networks’ PAN-OS software has been exploited by the Qilin ransomware gang to breach corporate networks, putting thousands of organizations and their sensitive data at risk. The bug, known as CVE-2026-0257, was identified back … Read more