Calling on Cyber Pros to Help Defend City Hall

Cybersecurity Expert Calls on Professionals to Help Defend Local Governments Against Cyber Threats A shocking case of cyber theft has highlighted a critical vulnerability in local governments across the United States. A small housing authority lost nearly a million dollars after attackers quietly infiltrated staff email accounts and rerouted funds meant for an affordable-housing project. … Read more

Critical Zimbra RCE flaw now actively exploited in attacks

A critical vulnerability in Zimbra Collaboration Suite (ZCS) has been actively exploited by attackers, putting hundreds of millions of users worldwide at risk. The Polish Computer Emergency Response Team (CERT Polska) has warned that unauthenticated attackers can gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications … Read more

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix NetScaler Flaws Leave Remote Access Systems Vulnerable, Urgent Patching Recommended A pair of newly disclosed vulnerabilities in Citrix’s NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances has left administrators scrambling to patch their systems. The flaws, which can be exploited remotely without authentication, highlight the ongoing threat posed by unpatched software … Read more

CISA warns of hackers exploiting critical MLflow vulnerability

Federal Agencies Under Attack: Critical MLflow Vulnerability Exploited by Hackers The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to federal agencies that threat actors are actively exploiting a critical vulnerability in the popular AI engineering platform, MLflow. The agency has added this flaw to its catalog of exploited vulnerabilities and ordered … Read more

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix Issues Urgent Warning for NetScaler Security Flaws, Patches Now Available Citrix has sounded the alarm, warning administrators to immediately patch two critical vulnerabilities affecting its NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The flaws, tracked as CVE-2026-19490 and CVE-2026-19489, can be exploited by attackers to bypass authentication or launch denial-of-service … Read more

How MSPs can catch phishing attacks email filters miss

**Phishing Attacks Get a Boost with AI – How MSPs Can Stay Ahead of the Game** Phishing attacks have always been a headache for Managed Service Providers (MSPs), but the recent surge in artificial intelligence-powered campaigns has made them even more challenging to detect and prevent. With AI, attackers can create highly personalized emails that … Read more

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A Critical Vulnerability in Elementor Pro Exposes WordPress Sites to Remote Code Execution Attacks A serious security bug has been discovered in the popular Elementor Pro plugin, which could allow attackers to upload malicious files and execute arbitrary code on vulnerable websites. The flaw, identified as CVE-2026-32475, affects all versions of Elementor Pro prior to … Read more

Hackers poison arrayref Rust crate to push infostealer malware

Cybersecurity experts have uncovered a sophisticated supply-chain attack that has compromised several popular Rust crates, including arrayref, append-only-vec, and internment. The attackers injected malicious code into these libraries, which are used by thousands of developers worldwide to build software applications. The hackers took advantage of the maintainer account behind arrayref, one of the most widely … Read more

How MSPs can catch phishing attacks email filters miss

Phishing Attacks Just Got a Whole Lot Smarter – And It’s Up to MSPs to Catch Them Cybersecurity professionals have long warned about the dangers of phishing emails, but recent advancements in artificial intelligence (AI) have made these attacks more convincing and harder to detect than ever. Managed Service Providers (MSPs), who are often responsible … Read more

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A Critical Elementor Pro Bug Exposes WordPress Sites to Remote Code Execution Attacks A severe vulnerability in the popular Elementor Pro plugin for WordPress has been uncovered, putting millions of websites at risk of remote code execution attacks. The flaw, identified as CVE-2026-32475, affects all versions of Elementor Pro prior to 4.2.2 and could allow … Read more