Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Sep 26, 2026
Vulnerability Critical Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involv
Weekly Threat Roundup: 2026-06-08 to 2026-06-14
Jun 14, 2026
roundup
Trending
Critical Cybersecurity roundup for 2026-06-08 to 2026-06-14. 4 CVE advisories, 3 breach reports, 5 threat news stories.
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
Jun 9, 2026
Vulnerability Critical Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS
Weekly Threat Roundup: 2026-04-27 to 2026-05-03
May 3, 2026
roundup
Trending
Critical Cybersecurity roundup for 2026-04-27 to 2026-05-03. 10 CVE advisories, 5 breach reports, 5 threat news stories.
SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack
Apr 29, 2026
Vulnerability Medium Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal credentials and authentication tokens from developers' systems. [...]
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)
Apr 27, 2026
Vulnerability Critical TeamPCP supply chain campaign resumed after a 26-day pause with three concurrent compromises (Checkmarx KICS, Bitwarden CLI, xinference PyPI). A new self-propagating npm worm, CanisterSprawl, has also been identified.
Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams
Mar 20, 2026
Vulnerability Medium Oracle has released an out-of-band security update to fix a critical unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager tracked as CVE-2026-21992. [...]
DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover
Mar 18, 2026
Vulnerability Medium The Interlock ransomware gang has been exploiting a maximum severity remote code execution (RCE) vulnerability in Cisco's Secure Firewall Management Center (FMC) software in zero-day attacks since lat
Google Fixes Two Chrome Zero-Days Exploited in the Wild Affecting Skia and V8
Mar 13, 2026
Vulnerability Medium Google has released emergency security updates to patch two high-severity Chrome vulnerabilities exploited in zero-day attacks. [...]
New 'LeakyLooker' Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries
High A new Android malware named BeatBanker can hijack devices and tricks users into installing it by posing as a Starlink app on websites masquerading as the official Google Play Store. [...]
Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials
Mar 9, 2026
Vulnerability Medium Hackers are increasingly exploiting newly disclosed vulnerabilities in third-party software to gain initial access to cloud environments, with the window for attacks shrinking from weeks to just days.
Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1
Mar 4, 2026
Vulnerability Medium A previously undocumented set of 23 iOS exploits named 'Coruna' has been deployed by multiple threat actors in targeted espionage campaigns and financially motivated attacks. [...]
APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2
High Google Chrome will shift from a four-week to a two-week release cycle to roll out new features, bug fixes, and performance improvements more frequently. [...]
New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
Mar 3, 2026
Vulnerability High Google has released security updates to patch 129 Android security vulnerabilities, including an actively exploited zero-day flaw in a Qualcomm display component. [...]