Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

3+ day, 6+ min ago   (436+ words) Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports. Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug…...

SecurityWeek
securityweek.com > fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

3+ day, 16+ hour ago   (429+ words) The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. Fortinet on Tuesday released patches for 10 vulnerabilities across its products, including critical security defects. The first critical bug, tracked as CVE-2026-84390 (CVSS score of 9.6), is…...

SecurityWeek
securityweek.com > new-phishing-attack-creates-malicious-pages-inside-the-victims-browser

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

3+ day, 20+ hour ago   (434+ words) Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. Future phishing campaigns may no longer involve a detectable physical web page. The attack flow…...

SecurityWeek
securityweek.com > chrome-153-patches-seventh-zero-day-of-2026

Chrome 153 Patches Seventh Zero-Day of 2026

3+ day, 20+ hour ago   (401+ words) The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. Google on Tuesday released Chrome 153 to the stable channel with patches for 230 vulnerabilities, including an exploited zero-day. Tracked as CVE-2026-87491, the medium-severity…...

SecurityWeek
securityweek.com > sap-patches-critical-extended-passport-processing-vulnerability

SAP Patches Critical Extended Passport Processing Vulnerability

4+ day, 15+ hour ago   (626+ words) Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. SAP released 20 new and updated security notes on Tuesday, including one that resolves a critical-severity memory corruption vulnerability. Tracked as…...

SecurityWeek
securityweek.com > mikrotik-patches-critical-flaws-chained-to-hack-routers

MikroTik Patches Critical Flaws Chained to Hack Routers

4+ day, 19+ hour ago   (570+ words) Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two…...

SecurityWeek
securityweek.com > north-korean-hackers-deploy-new-linux-espionage-toolkit

North Korean Hackers Deploy New Linux Espionage Toolkit

5+ day, 18+ hour ago   (735+ words) The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. North Korea-aligned threat actors have been using a new Linux toolkit in attacks targeting automotive and media organizations in South…...

SecurityWeek
securityweek.com > modified-screenconnect-clients-used-in-worm-like-campaign

Modified ScreenConnect Clients Used in Worm-Like Campaign

5+ day, 18+ hour ago   (646+ words) The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. Modified ScreenConnect clients are being used in an attack campaign to spread malicious payloads to other endpoints, cybersecurity firm Huntress warns. The worm-like attacks…...

SecurityWeek
securityweek.com > google-patches-6th-chrome-zero-day-of-2026

Google Patches 6th Chrome Zero-Day of 2026

1+ week, 1+ day ago   (383+ words) Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. Google on Thursday rolled out fresh Chrome 152 security updates that resolve 12 vulnerabilities, including an exploited zero-day. Tracked as CVE-2026-85046, the high-severity bug is described as…...

SecurityWeek
securityweek.com > malicious-virtualizor-update-served-via-bgp-hijacking

Malicious Virtualizor Update Served via BGP Hijacking

1+ week, 3+ day ago   (737+ words) Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. Softaculous’ Virtualizor users were served malicious software updates for two days after a threat actor diverted internet traffic to attacker-controlled servers. A…...