CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

A major security alert has been issued by CISA, with four actively exploited vulnerabilities added to its Known Exploited Vulnerabilities (KEV) catalog. The affected software includes Adobe’s ColdFusion, Joomla’s content management system, and Langflow, a popular video editing plugin. These vulnerabilities have been identified as being used in real-world attacks, making them high-priority targets for … Read more

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

A Critical Linux Flaw Lurks Undetected, Exposed After 15 Years A long-dormant vulnerability in the Ghostscript library, used by most Linux distributions to convert PostScript and PDF files, has been discovered to allow attackers to gain root access on affected systems. The flaw, which has existed for over 15 years, was unearthed recently by researchers … Read more

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

The China-linked threat actor known as UAT-7810 has expanded its ORB network with the introduction of new malware, dubbed LONGLEASH. This latest development highlights the evolving tactics employed by sophisticated nation-state actors and underscores the importance of staying vigilant in today’s increasingly complex cybersecurity landscape. UAT-7810 is a well-documented threat actor linked to China, known … Read more

Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security

Keyfactor Secures $1 Billion+ Investment for AI-Powered Post-Quantum Security Solution In a major development that highlights the growing urgency around post-quantum readiness, Keyfactor has secured a staggering investment exceeding $1 billion to accelerate its global operations and advance product innovation. The company’s end-to-end platform, known as the Trust Control Plane, provides centralized visibility into cryptographic … Read more

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

A newly disclosed Linux kernel vulnerability has left multi-tenant x86 public clouds vulnerable to a major security threat. Tracked as CVE-2026-53359, the flaw allows attackers to escape virtual machines (VMs) and execute code on the underlying host, posing a significant risk to cloud providers and their customers. The vulnerability, known as Januscape, affects the shadow … Read more

CISA orders feds to patch max severity ColdFusion flaw by Friday

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning to all federal government agencies in the United States: they must patch an extremely critical vulnerability in the Adobe ColdFusion web application development platform by this Friday. The flaw, identified as CVE-2026-48282, is being actively exploited by malicious actors, and CISA has … Read more

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The US Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the continued threat posed by software weaknesses in widely used applications such as Adobe, Joomla, and Langflow. This move underscores the urgent need for organizations to prioritize vulnerability patching and risk mitigation. The … Read more

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

A devastating 15-year-old vulnerability, dubbed GhostLock, has been discovered to allow attackers to break free from even the most secure Linux environments, gaining root-level access and compromising entire systems. The flaw affects a staggering majority of Linux distributions in use today, leaving countless organizations vulnerable to exploitation. GhostLock exploits a fundamental weakness in the way … Read more

CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker

Tarah Wheeler’s Unlikely Path to Cybersecurity Leadership Meet Tarah Wheeler, Chief Information Security Officer (CISO) at TPO Group, a leading cybersecurity consultancy firm that serves high-stakes organizations such as critical industries and federal agencies. What sets Wheeler apart is her unconventional journey into the world of cybersecurity, which she describes as an “alleyway” where she … Read more

Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks

Iran-Linked Hackers Unleash Sophisticated Cyberattacks on Israeli Targets A highly skilled and secretive group of hackers linked to Iran’s Ministry of Intelligence and Security (MOIS) has been conducting a series of complex cyberattacks against organizations in Israel. Dubbed “Cavern Manticore” by cybersecurity experts, this advanced persistent threat (APT) actor uses a modular command-and-control framework that … Read more