CISA orders feds to patch max severity ColdFusion flaw by Friday

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning to all federal government agencies in the United States: they must patch an extremely critical vulnerability in the Adobe ColdFusion web application development platform by this Friday. The flaw, identified as CVE-2026-48282, is being actively exploited by malicious actors, and CISA has … Read more

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The US Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the continued threat posed by software weaknesses in widely used applications such as Adobe, Joomla, and Langflow. This move underscores the urgent need for organizations to prioritize vulnerability patching and risk mitigation. The … Read more

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

A devastating 15-year-old vulnerability, dubbed GhostLock, has been discovered to allow attackers to break free from even the most secure Linux environments, gaining root-level access and compromising entire systems. The flaw affects a staggering majority of Linux distributions in use today, leaving countless organizations vulnerable to exploitation. GhostLock exploits a fundamental weakness in the way … Read more

CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker

Tarah Wheeler’s Unlikely Path to Cybersecurity Leadership Meet Tarah Wheeler, Chief Information Security Officer (CISO) at TPO Group, a leading cybersecurity consultancy firm that serves high-stakes organizations such as critical industries and federal agencies. What sets Wheeler apart is her unconventional journey into the world of cybersecurity, which she describes as an “alleyway” where she … Read more

Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks

Iran-Linked Hackers Unleash Sophisticated Cyberattacks on Israeli Targets A highly skilled and secretive group of hackers linked to Iran’s Ministry of Intelligence and Security (MOIS) has been conducting a series of complex cyberattacks against organizations in Israel. Dubbed “Cavern Manticore” by cybersecurity experts, this advanced persistent threat (APT) actor uses a modular command-and-control framework that … Read more

Critical Adobe ColdFusion Vulnerability Exploited in Attacks

A recently patched vulnerability in Adobe ColdFusion has been exploited by threat actors just two hours after its public disclosure. The flaw, tracked as CVE-2026-48282 and carrying a maximum severity rating of CVSS 10/10, allows for arbitrary code execution and was quickly identified by the vulnerability intelligence platform KEVIntel. The security defect is described as … Read more

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has enlisted the powerful AI-driven tool Mythos from Anthropic to scan and audit federal government software for security vulnerabilities. This move is part of a proactive effort to identify and patch potential weaknesses that could be exploited by foreign intelligence agencies or cybercriminals. According to sources familiar … Read more

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Cybersecurity researchers are sounding the alarm about a critical flaw in Gitea, an open-source platform used for hosting git repositories. Threat actors have been actively exploiting this vulnerability, which allows unauthorized access to internet-accessible instances of Gitea. The issue affects all versions of Gitea prior to 1.26.3, and is tracked as CVE-2026-20896 with a CVSS … Read more

Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks

Iran-Linked Hackers Wield Sophisticated Modular Framework in Targeted Cyberattacks A highly advanced Iranian hacking group has been using a cutting-edge, modular command-and-control (C&C) framework to infiltrate and compromise organizations in Israel. Dubbed Cavern Manticore by cybersecurity researchers at Check Point, this sophisticated threat actor focuses its attacks on government entities and IT providers, raising concerns … Read more

Critical Adobe ColdFusion Vulnerability Exploited in Attacks

A Critical Adobe ColdFusion Vulnerability Has Been Exploited in Attacks, Despite Being Recently Patched Threat actors have begun exploiting a critical vulnerability in Adobe’s ColdFusion platform, despite it being patched just two weeks ago. The flaw, tracked as CVE-2026-48282, is described as a path traversal that could lead to arbitrary code execution and has been … Read more