Threats & incidents
-
Ransomware exploits SonicWall remote-access flaws
CISA says two previously exploited SonicWall SMA1000 vulnerabilities are now associated with ransomware activity, escalating weaknesses in infrastructure that controls privileged remote access.
-
Russian hackers turn recruitment into access route
CERT-UA says a Russian military-linked threat cluster is approaching Ukrainian IT professionals through legitimate recruitment channels before steering candidates towards malicious technical assessments.
-
Russian hackers turn recruitment into access route
CERT-UA says a Russian military-linked threat cluster is approaching Ukrainian IT professionals through legitimate recruitment channels before steering candidates towards malicious technical assessments.
-
CEVA attack spreads through European supply chains
A cyberattack affecting eight CEVA Logistics warehouses has disrupted European fulfilment and exposed customer information held on behalf of retailers, a bank, a football club, and Valve.
-
Second Polish heat plant attack exposes OT route
CERT Polska has reconstructed a destructive attack on a heat plant serving 50,000 residents, exposing an unexpected route into operational technology through misconfigured private mobile connectivity.
-
LoadMaster flaw enters exploited catalogue
CISA has added critical LoadMaster command-injection flaw CVE-2026-8037 to its exploited-vulnerability catalogue, advancing the evidence beyond the unsuccessful attack attempts reported earlier this summer.
-
macOS Screen Sharing flaw bypasses authentication
Apple has patched a Screen Sharing authentication flaw as independent research describes a deeper pre-authentication route capable of reaching remote code execution on exposed, unpatched Macs.
-
TrueConf compromise turns updates into attack route
Kaspersky says attackers compromised unpatched TrueConf servers and replaced legitimate client installers with backdoored versions, extending exposure from server operators to organisations connecting through affected counterparties.
-
Stade Français contains attack on internal systems
Stade Français says a cyberattack affected part of its information system while ticketing and merchandise remained available, as separate claims about leaked player documents remain unconfirmed by the club.
-
Metabase zero-day reaches n8n user data
A zero-day attack on Metabase Cloud reached data available through German automation company n8n’s analytics environment, exposing how an internal reporting dependency can become a route into user and credential information.






