Daily News
SonicWall SMA1000 RCE Vulnerability: Patch Now
A new SonicWall SMA1000 RCE vulnerability is under active exploitation: an unauthenticated server-side request forgery chained with an OS command injection lets an attacker take full root-level control of the appliance with no login required. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, with a federal deadline of September 5,…
Read MoreBoston Scientific Cyberattack Halts Global Shipments
A Boston Scientific cyberattack detected on August 25 has caused what the company itself calls a “global disruption” — halting order processing and shipping for one of the world’s largest manufacturers of pacemakers, defibrillators, stents and other implantable medical devices, with no confirmed restoration timeline more than a week later. What Happened The Boston Scientific…
Read MoreJFrog Artifactory Authentication Bypass Exploited
A JFrog Artifactory authentication bypass is now under active exploitation: attackers are minting themselves unauthenticated administrator tokens on self-hosted Artifactory instances just days after JFrog disclosed the flaw. Tracked as CVE-2026-82329 (CVSS 9.8), the bug sits in Artifactory’s default, out-of-the-box configuration — no misconfiguration required, no credentials needed. What Happened JFrog disclosed the JFrog Artifactory…
Read MoreMcKesson Breach: How the Okta Vishing Attack Happened
An Okta vishing attack — a phone call, not a piece of malware — is how the extortion group ShinyHunters claims it broke into US healthcare and pharmaceutical distribution giant McKesson. McKesson has confirmed unauthorized access to third-party applications and data exfiltration, but has not confirmed the attack path itself: according to ShinyHunters’ own account,…
Read MoreExchange Authentication Bypass Vulnerability Now Exploitable
A working exploit for an Exchange authentication bypass vulnerability is now public on GitHub, and heise.de reports that roughly 85% of on-premises Exchange servers in Germany remain vulnerable three weeks after Microsoft shipped a fix. The catch: for organizations still running Exchange 2016 or 2019, that fix is locked behind Microsoft’s paid Extended Security Update…
Read More
