PaperCut NG/MF Critical Zero-Day Exploited in the Wild

On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At Read More …

An open letter for a global surge in cyber defense

We have a limited window to strengthen cyber defenses. In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on—from Read More …

‘Proactive SIM’ cards can hijack smartphones, IoT devices and even EV chargers

A malicious SIM card can instruct the device it sits in to run commands of an attacker’s choosing, and on the cellular modules embedded in electric vehicle chargers, industrial routers, and car telematics units, essentially allowing it to take the Read More …

UK MoD says no data leaked to China via drone vulnerability

Britain’s Ministry of Defence said on Monday that there is no evidence that military data was compromised after a cyber vulnerability was discovered in Royal Navy drones. The issue was identified during routine cybersecurity testing, the ministry said, adding that Read More …

Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks

Two Polish security researchers wanted to find out how vulnerable their country’s internet was to potential cyberattacks and quickly found that thousands of public agencies and websites were at risk of being hacked. At the Def Con cybersecurity conference in Read More …

FBI: Cyber Criminal Group TeamPCP

The Federal Bureau of Investigation (FBI) is releasing this FLASH to highlight the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with the cyber criminal group TeamPCP. TeamPCP actors have conducted large-scale software supply chain compromises by Read More …

Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk

The CVE-2024-2658 vulnerability was discovered in 2024 within the FlexNet Publisher component of the Schneider Electric Floating License Manager. This software handles license management across various Schneider Electric products used for comprehensive industrial automation ranging from PLC programming to centralized control Read More …

Cisco SD-WAN make-me-root bug under attack

Cisco today issued a fix for a Catalyst SD-WAN Manager bug that attackers have already spotted and exploited to get root privileges, according to both the networking vendor and the feds. The vulnerability, tracked as CVE-2026-20262, is in the web UI of Read More …

CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation

Rapid7 Senior Principal Security Researcher Stephen Fewer discovered CVE-2026-0826, a critical unauthenticated stack-based buffer overflow vulnerability affecting multiple HP Poly VoIP devices. If you’ve been around vulnerability research long enough, the bug class here is going to feel very familiar. And Read More …

Microsoft under fire for threatening security researcher with criminal investigation

After a security researcher published a series of unpatched bugs in Microsoft products, along with code to exploit them, the company is now threatening to take legal action and call the cops on them. Microsoft’s veiled threat reignites a long-running Read More …