access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure injection intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…
-
Calling on Cyber Pros to Help Defend City Hall
Government agencies with smaller budgets need support, and here’s how you can help. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/calling-on-cyber-pros-to-help-city-hall also interesting: Severe Vulnerabilities in Consilium CS5000 Fire Panels Allow Remote System Takeover Iran-Nexus Hackers Impersonate Omani MFA to Target Governments Entities Full renewal of state and local cyber grants program passes in House…
-
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development…
-
Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist
Tags: threatKyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. First seen on cyberscoop.com Jump to article: cyberscoop.com/764-member-sentenced-longest-prison-sentence-kyle-spitze/ also interesting: China Steals Defense Secrets ‘on Industrial Scale’ Mehr Wissen über Cyber-Bedrohungen – Das sind die verschiedenen Arten der Threat-Intelligence…
-
Money and Mindset: The Two Biggest Roadblocks to Cyber Policing
Law enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes, though officers really only need to learn the basics, but focus and budgets hinder progress. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/money-and-mindset-the-two-biggest-roadblocks-to-cyber-policing also interesting: Want to be a cybersecurity pro? Use generative AI to get some simulated training Cybersecurity…
-
N-able Bug Exposes Password Vault Master Keys
The popular Passportal password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely? First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/n-able-bug-password-vault-master-keys also interesting: 5 ways to strengthen identity security and improve attack resilience 5 ways to strengthen identity…
-
Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers’ systems during compilation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/ also interesting: North Korean crypto thieves deploy custom Mac backdoor ScarCruft Hacker Group Launches New Rust-Based Malware Attack Leveraging PubNub Hackers abused React Native CLI…
-
Windows 11 Hotpatching Explained: How Much Does It Really Reduce Reboots?
Windows 11 hotpatching can install security updates without reboots. Learn who qualifies, how the update cycle works, and what IT teams should expect. The post Windows 11 Hotpatching Explained: How Much Does It Really Reduce Reboots? appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-windows-11-hotpatching-reboots/ also interesting: Windows Server 2025 gets hotpatching…
-
Oracle Patches 943 Vulnerabilities, Including Critical WebLogic Bugs
Oracle patched 943 vulnerabilities, including critical remotely exploitable flaws. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/oracle-patches-943-vulnerabilities-including-critical-weblogic-bugs/ also interesting: U.S. CISA adds Apple, Oracle Agile PLM bugs to its Known Exploited Vulnerabilities catalog Clop Attacks Against Oracle E-Business Suite Trace to July Oracle E-Business Suite Vulnerability Exploited In Ransomware Attacks Oracle October 2025 Critical Patch…
-
Apple Patches Critical iPhone Flaws: Attackers Could Run Malicious Code
Apple patched critical iPhone flaws that could allow malicious code execution, including an ImageIO vulnerability. Here’s what users should know. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-apple-critical-iphone-security-flaws-august-2026/ also interesting: Safari Vulnerability Exposes EU iOS Users to Malicious Marketplaces Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More iPhone users targeted in Apple’s first…
-
Cryptohack Roundup: Harmony’s Post-Exploit Blockchain Rollback
Also: Fake Web3 Interview Led to Wallet Theft, Delio CEO’s 15-Yr Sentence. This week, Harmony to roll back blockchain after exploit, Delio CEO sentenced to 15 years in South Korea, an alleged Ponzi promoter deported to the United States, SafePal and Trezor customers’ data exposed, and attackers exploited a Mac flaw to mine Monero. First…
-
NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs
NSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning of an active hacking campaign against Siemens S7 Series programmable logic controllers. The advisory, CISA AA26-231A, is co-signed by NSA, FBI, DOE, and EPA…
-
Is Cyber missing the Marque?
In this week’s newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/is-cyber-missing-the-marque/ also interesting: HostBreach Offers Free Cyber Snapshot For CMMC Compliance Requirements Hackers Breach Intelligence Portal…
-
Top 5 Enterprise CIAM Platforms in 2026: In-Depth Comparison
Auth0, Microsoft Entra External ID, Ping Identity, IBM Verify, and WSO2 compared for 2026: analyst rankings, agentic-identity launches, pricing, and which platform fits which enterprise. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/top-5-enterprise-ciam-platforms-in-2026-in-depth-comparison/ also interesting: Cybersecurity Snapshot: Top Guidance for Improving AI Risk Management, Governance and Readiness Cybersecurity Snapshot: Global Agencies Target Criminal “Bulletproof” Hosts,…
-
Palo Alto Launches Frontier AI Critical Defense Program to Scale Virtual Patching
Frontier AI’s ability to find vast numbers of previously unknown vulnerabilities has created a timing problem for defenders. How can they protect vulnerable software and devices when discovery is accelerating but permanent patching can still take hours, days or weeks? Palo Alto Networks is now betting on virtual patching as a way to cut that..…
-
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The U.S. government on Wednesday warned of an “active threat” targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts.The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That First seen on thehackernews.com Jump to article: thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html…
-
Senators press TikTok over withholding of safety features for some users
Tags: unclassifiedIn a letter on Wednesday, Sens. Marsha Blackburn (R-TN) and Richard Blumenthal (D-CT) criticized the company for having “knowingly withheld a critical safety measure for millions of American users.” First seen on therecord.media Jump to article: therecord.media/senators-press-tiktok-over-withholding-safety-features also interesting: Datenschutzverstoß: Dresdner IT-Administrator kopierte massenhaft Wählerdaten Wait… Did Pagers Get Hacked To Blow People Up? Wiz…
-
OpenAI Unveils Private Safety Processing to Detect AI Misuse Without Storing Enterprise Data
OpenAI announced Wednesday that it is testing a new security protocol designed to protect enterprise privacy without compromising system safety. The feature, Private Safety Processing, would allow businesses to deploy highly advanced frontier artificial intelligence (AI) models while maintaining a policy of Zero Data Retention (ZDR). The move highlights a growing rift between Silicon Valley’s..…
-
US man sentenced to 77 years for child sexual abuse tied to online extremist group
Kyle Spitze of Tennessee faced federal charges for targeting girls online as part of ‘764 network’ investigated by FBIA 27-year-old Tennessee man described by the US justice department as a “nihilistic violent extremist” was sentenced to 77 years in prison on Wednesday for his targeting of girls online as part of <a href=”https://www.theguardian.com/technology/ng-interactive/2026/jul/21/764-network-gamification-of-harm-the-com-cybercrime-ntwnfb”>the 764 network,…
-
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI has disclosed an attack technique that it says can cause xAI’s Grok chatbot to send a user’s name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page.The AI security company, which has codenamed the technique “Cryptographic…
-
Hackers Actively Target Siemens PLCs With AI Cyberattacks
‘We Are Crossing a Threshold’ Warns Critical Infrastructure Security Expert. An artificial intelligence-assisted cyberattack campaign is targeting widely used online operational technology devices made by Siemens, the U.S. cyber defense agency warned Wednesday – the first time it’s called out an AI-assisted cyber campaign against OT. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hackers-actively-target-siemens-plcs-ai-cyberattacks-a-32616 also…
-
T-Mobile Cuts Network Cable to Stop Salt Typhoon Hackers
T-Mobile physically cut a network cable to disrupt Salt Typhoon’s access. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/t-mobile-cuts-network-cable-to-stop-salt-typhoon-hackers/ also interesting: Salt Typhoon Campaign: A Wake-Up Call for U.S. Telecoms and National Security NDSS 2025 Power-Related Side-Channel Attacks Using The Android Sensor Framework Keenadu: Android malware that comes preinstalled and can’t be removed by users…
-
Why MSPs Need Visibility Across ‘Every AI Surface’: KIPIO CEO
Amid the AI adoption rush, the usage of LLM-powered tools in unsanctioned or insecure ways poses a massive risk for MSPs and their clients, according to KIPIO co-founder and CEO Emily Hock. First seen on crn.com Jump to article: www.crn.com/news/security/2026/why-msps-need-visibility-across-every-ai-surface-kipio-ceo also interesting: Top 10 Cybersecurity Predictions for 2026 TDL 019 – The Psychology Behind a…
-
Machine-Speed Credential Abuse: What the ChainDrop npm Worm Changes
ChainDrop hijacked 444 npm packages and 2B monthly downloads via a Claude Code hook. AI agents have collapsed the gap between credential theft and abuse First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/machine-speed-credential-abuse-what-the-chaindrop-npm-worm-changes/ also interesting: The 2024 cyberwar playbook: Tricks used by nation-state actors Modern supply-chain attacks and their real-world impact Q1 2026 Open Source…
-
What Belongs Inside the Company AI Operating System?
In the last post, I argued that AI maturity is not about tool count. The real question is whether AI is changing how the company works. That leads to the next question: if AI is becoming a company operating system layer, what actually belongs inside that layer? The answer is not “a chatbot for every……
-
Horizon3.ai alternatives in 2026: Escape vs NodeZero and 4 more tools
Escape is the best Horizon3.ai alternative for continuous AI pentesting across APIs, web apps, and complex authentication, including regression testing, developer-ready remediation, and platform pricing suited for rapidly scaling orgs. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/horizon3-ai-alternatives-in-2026-escape-vs-nodezero-and-4-more-tools/ also interesting: An open letter to FireTail customers about security and data privacy FireTail Blog MCP is…
-
Horizon3.ai alternatives in 2026: Escape vs NodeZero and 4 more tools
Escape is the best Horizon3.ai alternative for continuous AI pentesting across APIs, web apps, and complex authentication, including regression testing, developer-ready remediation, and platform pricing suited for rapidly scaling orgs. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/horizon3-ai-alternatives-in-2026-escape-vs-nodezero-and-4-more-tools/ also interesting: An open letter to FireTail customers about security and data privacy FireTail Blog MCP is…
-
ChatGPT for Teens tackles risky chats and homework shortcuts
OpenAI has strengthened ChatGPT’s protections for teens, but some of its strongest parental controls still depend on linked accounts. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/chatgpt-for-teens-tackles-risky-chats-and-homework-shortcuts/ also interesting: Microsoft Adds Inline Data Protection to Edge for Business to Block GenAI Data Leaks Is attacker laziness enabled by genAI shortcuts making them easier to catch?…
-
The Trust Gap Filigran Found at Black Hat
Tags: detectionWalk the floor at Black Hat long enough, and the pitches start to blur. Everyone is touting better visibility, faster detection, and sharper prioritization. But a few feet away from the booths, the conversations become more interesting. Practitioners and senior decision-makers from the same organizations describe their exposure management programs in different terms, and the..…
-
CMMC 2.0 Audits: Lazarus Alliance Cybersecurity Assessments
In 2026, defense contractors face a decisive shift where CMMC 2.0 audits move beyond documentation reviews to real-time validation of integrated risk controls. Lazarus Alliance delivers assessments that embed NIST 800-171 controls into enterprise governance, revealing gaps that traditional audits overlook. CMMC 2.0 Final Rule Implementation: Strategic Implications for 2026 The CMMC 2.0 Final Rule,”¦…
-
CMMC 2.0 Audits: Lazarus Alliance Cybersecurity Assessments
In 2026, defense contractors face a decisive shift where CMMC 2.0 audits move beyond documentation reviews to real-time validation of integrated risk controls. Lazarus Alliance delivers assessments that embed NIST 800-171 controls into enterprise governance, revealing gaps that traditional audits overlook. CMMC 2.0 Final Rule Implementation: Strategic Implications for 2026 The CMMC 2.0 Final Rule,”¦…
-
BSidesSF 2026 From Noise To Notes: Orchestrating SAST With Developers Through AI-Driven Remediation
Tags: aiPresenter: Adrián Puente Z. Our thanks to Security BSides San Francisco for publishing their Creators, Authors and Presenter’s outstanding BSidesSF 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidessf-2026-from-noise-to-notes-orchestrating-sast-with-developers-through-ai-driven-remediation/ also interesting: How AI is Changing the Game for SaaS Sales Teams Many IT leaders click phishing links, and…
-
Essential Cybersecurity Audits for Regulated Industries by Continuum GRC
In 2026, organizations operating in regulated industries face an increasingly complex web of cybersecurity audits driven by evolving threats and stricter enforcement of frameworks like CMMC 2.0 and NIST SP 800-171 Rev 3. Cybersecurity audits have become essential not merely for checkbox compliance but for establishing robust governance that protects sensitive data and maintains operational”¦…
-
Cribl Acquires AI Assets from Radiant Security to Further SOC Ambitions
Cribl this week revealed it has acquired technology assets from Radiant Security that will provide the foundation for building a security operations center (SOC) based on artificial intelligence (AI). The AI technologies acquired from Radiant Security enable AI agents to autonomously triage, investigate, and resolve security alerts. Cribl, via the acquisition of this intellectual property,..…
-
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/ also interesting: Wordfence blocks 8.7M attacks exploiting old GutenKit and Hunk Companion flaws Wordfence blocks 8.7M attacks exploiting old GutenKit and Hunk Companion flaws…
-
ICO police facial recognition audits reveal ‘mixed’ bag
Tags: dataThe use of facial recognition technologies by UK police forces requires ‘significant improvements’ to ensure accountability and public trust, says data regulator First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649479/ICO-police-facial-recognition-audits-reveal-mixed-bag also interesting: Hackers Claim Access to Nokia Internal Data, Selling for $20,000 Biden Crack Down Sale of Americans’ Personal Data to China Russia Critical Linux…
-
Retail theft bill spurs ‘very large and very dangerous’ surveillance fears
The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate, and supporters say it could help fight cybercrime. First seen on cyberscoop.com Jump to article: cyberscoop.com/corca-retail-theft-bill-ice-surveillance/ also interesting: Cybercrime groups team with organized crime in massive cargo theft campaigns Crypto-less Crypto Investment Scams:…
-
Fitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacks
Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/water-healthcare-cyberattacks-credit-ratings-fitch/828384/ also interesting: The UK’s Cyber Security and Resilience Bill will boost standards and increase costs The Biggest Cyber Stories of the Year: What 2025 Taught Us When Your Own Eyes…
-
Neuer Job als Leiter*in Kundenservice / IT-Servicemanagement gesucht? Schau dir unsere Top Jobs an
Tags: jobsFirst seen on t3n.de Jump to article: t3n.de/news/unsere-jobs-der-woche-1175973/ also interesting: Women in Cyber Security on the Rise, But Facing More Layoffs and Budget Cuts Than Men Docker APIs Targeted FireTail Blog Software developers: Prime cyber targets and a rising risk vector for CISOs US joins nearly two dozen other countries in striking back against DDoShire…
-
200 Konten kompromittiert – Angriff auf SharePoint-Server der Schweizer Regierung
First seen on security-insider.de Jump to article: www.security-insider.de/schweizer-bundesverwaltung-sharepoint-hack-200-konten-a-0235df375211268ec50b84b703aed634/ also interesting: DDoS-Angriffe auf Websites der nepalesischen Regierung Russia fires its biggest cyberweapon against Ukraine Öffentliche Verwaltung im Visier von Cyberspionen Top 10 Cybersecurity Predictions for 2026
-
JFrog Artifactory Flaws Enable Software Supply Chain Attacks
Two Artifactory flaws allowed attackers to poison package metadata across software repositories First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/jfrog-flaws-software-supply-chain/ also interesting: Cybersecurity Snapshot: CISA’s Best Cyber Advice on Securing Cloud, OT, Apps and More OpenAI launches Aardvark to detect and patch hidden bugs in code CI/CD Under Attack: What the AWS CodeBuild “CodeBreach” Flaw…
-
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment.The vulnerability (“GHSA-864f-rcv7-6rh4”), which has yet to be assigned a CVE identifier, impacts all versions of the library before and…
-
Your Mac already has a built-in firewall. Here’s how to get more from it
Tags: firewallMalwarebytes Firewall gives you a clearer, more intuitive way to manage your Mac’s inbuilt firewall. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/your-mac-already-has-a-built-in-firewall-heres-how-to-get-more-from-it/ also interesting: Are LLM firewalls the future of AI security? How to Run a Firewall Test: A Guide for Enterprises Warnings about Cisco vulns under active exploit are falling on deaf ears…
-
CAPTCHA Has Fallen Behind Biometric Check is Built for Today’s Traffic
Key Takeaways Most bot management vendors still fall back on CAPTCHA or SMS codes when traffic looks suspicious, friction that AI now defeats more reliably than the humans it was built to test. A 2023 UC Irvine study found bots solving CAPTCHA at 99.8% accuracy against a 5084% human range. CAPTCHA is a browser… First…
-
Softwareprojekte gefährdet: Angriffe auf Gitlab beobachtet
Angreifer können durch eine Sicherheitslücke auf Gitlab-Instanzen verheerende Schäden anrichten. Attacken laufen bereits. First seen on golem.de Jump to article: www.golem.de/news/kritische-sicherheitsluecke-hacker-attackieren-gitlab-instanzen-2608-212127.html also interesting: CISA warnt: Microsoft Smartcreen- und Gitlab-Sicherheitslücke werden angegriffen Ungepatchte Lücken ermöglichen Übernahme von GitLab-Konten Softwareprojekte gefährdet: Angriffe auf Gitlab beobachtet Versteckter Angriff auf Linux-Systeme: So verhinderte ein Programmierer weltweite Schäden
-
Softwareprojekte gefährdet: Angriffe auf Gitlab beobachtet
Angreifer können durch eine Sicherheitslücke auf Gitlab-Instanzen verheerende Schäden anrichten. Attacken laufen bereits. First seen on golem.de Jump to article: www.golem.de/news/kritische-sicherheitsluecke-hacker-attackieren-gitlab-instanzen-2608-212127.html also interesting: CISA warnt: Microsoft Smartcreen- und Gitlab-Sicherheitslücke werden angegriffen Ungepatchte Lücken ermöglichen Übernahme von GitLab-Konten Softwareprojekte gefährdet: Angriffe auf Gitlab beobachtet Kritische Sicherheitslücke in FortiClientEMS wird angegriffen
-
An Air Gap Doesn’t Remove the Supply Chain. It Makes Every Crossing a Decision.
Tags: network<div cla For years, air-gapped environments have been the gold standard for protecting classified systems and critical infrastructure. Isolate the network, remove the path, reduce the risk. The logic held, and it still does. An air gap does exactly what it was designed to do. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/an-air-gap-doesnt-remove-the-supply-chain-it-makes-every-crossing-a-decision/ also interesting:…
-
Twitch wants your content for Amazon AI training. Here’s how to opt out
Twitch added an option to opt out of training Amazon AI with your content”, two years after it confirmed that training had begun. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/twitch-wants-your-content-for-amazon-ai-training-heres-how-to-opt-out/ also interesting: X faces GDPR complaints for unauthorized use of data for AI training Phishing training needs a new hook, here’s how to rethink…
-
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution.”A remote code execution vulnerability exists in…

