Data & infrastructure
-
Exchange outage exposes Microsoft 365 dependency
A multi-hour Exchange Online incident is disrupting email, authentication, and administration as Microsoft tests remediation for a problem involving an authentication component.
-
New Nodemailer CVEs formalise patched flaws
Six Nodemailer vulnerabilities have received CVE assignments, consolidating previously disclosed flaws involving server-side file access, SSRF, TLS validation, and message handling.
-
Fire Ant targets trusted network infrastructure
Sygnia says the China-nexus actor it tracks as Fire Ant is compromising routers, authentication systems, and Linux management hosts to reach connected high-value environments.
-
Missed TeamCity patch exposed JetBrains Cadence
JetBrains says attackers exploited an unpatched TeamCity vulnerability in its Cadence service, exposing customer data, cloud identities, and credentials contained in an older server backup.
-
ServiceNow fixes three maximum-severity flaws
ServiceNow has patched three AI Platform vulnerabilities rated CVSS 10.0 that can expose instance data, enable privilege escalation, or permit arbitrary database operations without authentication.
-
PaperCut attacks expose pre-authentication route
PaperCut is responding to active attacks against NG and MF after researchers reproduced a pre-authentication route from configuration manipulation to arbitrary code execution.
-
Plesk flaws break hosting tenant boundaries
Two Plesk vulnerabilities can expose other customers’ databases and server files, turning ordinary hosting accounts into a route towards cross-tenant access and administrative compromise.
-
Ubiquiti discloses 22 UniFi security flaws
Ubiquiti has published a 22-part security bulletin covering UniFi products, including critical vulnerabilities capable of command execution and privilege escalation on network infrastructure.
-
Dutch NCSC flags serious DrayTek flaws
Dutch cyber authorities are urging DrayTek VigorAP and VigorSwitch users to update after warning that serious flaws could expose network devices to takeover, disruption, or data access.
-
Apollo breach exposes cloud identity risk
Apollo Global Management says a social-engineering incident gave attackers access to cloud platforms for several days and exposed sensitive personal information.










