ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

A massive IoT botnet has been uncovered, compromising over 296,000 devices worldwide. What’s more alarming is that hundreds of water treatment systems have been targeted, raising concerns about the potential for catastrophic damage and even loss of life. Meanwhile, a critical vulnerability in Microsoft’s SharePoint platform has been discovered, allowing attackers to remotely execute code … Read more

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Critical Vulnerabilities in Next.js Framework Expose Developers and End-users to Remote Code Execution Attacks A severe security flaw has been discovered in the popular Next.js framework, a widely used JavaScript library for building server-side rendered websites. The vulnerability, which affects all versions of Next.js prior to 13.1.5, allows attackers to execute arbitrary code on affected … Read more

PaperCut warns of NG, MF flaw exploited in zero-day attacks

PaperCut Warns of Zero-Day Attacks Exploiting NG, MF Flaw, Urges Immediate Action A critical vulnerability in PaperCut’s print management software has been exploited in zero-day attacks, leaving organizations with Internet-exposed Application Servers vulnerable to compromise. The company behind the software, PaperCut, has issued an urgent security advisory warning customers of confirmed incidents and urging them … Read more

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

A new strain of malware, known as GoCaracal, has been discovered using Ethereum smart contracts to fetch replacement command and control (C2) addresses. This sophisticated tactic allows attackers to evade detection by constantly changing their C2 infrastructure, making it challenging for security teams to track and contain the attacks. GoCaracal malware is a type of … Read more

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Amazon’s Kiro platform has been found vulnerable to a novel type of attack, dubbed “Kiro Prompt Injection.” This sophisticated technique allows malicious actors to exfiltrate sensitive data from organizations using Amazon’s services. The exploit takes advantage of a feature designed to streamline workflows within Kiro Powers, but instead enables attackers to bypass security controls and … Read more

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

A massive IoT botnet has compromised over 296,000 devices, with hackers targeting critical infrastructure such as water treatment systems in multiple countries. Meanwhile, a vulnerability in Microsoft’s SharePoint platform allows attackers to execute remote code on affected servers, creating a potential gateway for further exploitation. The IoT botnet, which cybersecurity researchers have been tracking for … Read more

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Next.js Developers Left Reeling as Critical AVIF and Windows Flaws Exposed A critical vulnerability in the widely-used Next.js framework has left developers scrambling for patches, as researchers disclosed two severe flaws that enable unauthenticated remote code execution (RCE). The issue affects multiple platforms, including Linux and Windows machines, putting sensitive data at risk of exploitation. … Read more

Manchester Airports Group says hackers stole travelers’ data

A massive data heist has struck one of the UK’s largest airport operators, leaving millions of travelers’ personal details vulnerable to cyber threats. The Manchester Airports Group (MAG) has confirmed that hackers breached its systems and stole customer data from airports in Manchester, Stansted, and East Midlands. The attackers managed to exfiltrate a wide range … Read more

What the Data Says About AI in Security Operations in 2026

Cybersecurity experts are sounding the alarm over a disturbing trend: identity exposure is being used as a key component in active attack paths, allowing hackers to breach even the most secure systems. The data tells a stark story – 11 real-world cases have revealed that attackers are exploiting exposed identities to compromise entire networks. The … Read more