Vulnerabilities F5 BIG-IP DoS Flaw Upgraded to Critical RCE, Now Exploited in the Wild Initially disclosed as a high-severity denial-of-service (DoS), the bug was reclassified as a critical RCE issue. Ionut ArghireMarch 30, 2026
Cybercrime Pro-Iranian Hacking Group Claims Credit for Hack of FBI Director Kash Patel’s Personal Account The group that it was making available for download emails and other documents from Patel’s account. Associated PressMarch 27, 2026
Management & Strategy RSAC 2026 Conference Announcements Summary (Days 3-4) A summary of the announcements made by vendors on the third and fourth days of the RSAC 2026 Conference. SecurityWeek NewsMarch 27, 2026
Incident Response CISA Flags Critical PTC Vulnerability That Had German Police Mobilized Police in Germany physically warned organizations about the critical PTC Windchill vulnerability tracked as CVE-2026-4681. Eduard KovacsMarch 27, 2026
Nation-State Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure The state-sponsored threat actor deployed kernel implants and passive backdoors enabling long-term, high-level espionage. Ionut ArghireMarch 26, 2026
Disaster Recovery Dell and HP Roll Out Quantum-Resistant Device Security The computer giants have announced new security capabilities for PCs and printers. Eduard KovacsMarch 26, 2026
Artificial Intelligence AI Speeds Attacks, But Identity Remains Cybersecurity’s Weakest Link PwC finds AI is amplifying speed and scale of attacks, as identity theft evolves into a cybercriminal supply chain. Kevin TownsendMarch 25, 2026
Endpoint Security iOS, macOS 26.4 Roll Out With Fresh Security Patches Apple released security fixes for older devices as well, in iOS 18.7.7, iPadOS 18.7.7, macOS Sequoia 15.7.5, and macOS Sonoma 14.8.5. Ionut ArghireMarch 25, 2026
Application Security From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$. Ionut ArghireMarch 25, 2026
Government DoE Publishes 5-Year Energy Security Plan CESER’s Project Armor is a five year initiative to harden the US critical energy infrastructure, including strengthening energy systems ‘to prevent and recover from... Kevin TownsendMarch 24, 2026
Management & Strategy RSAC 2026 Conference Announcements Summary (Day 1) A summary of the announcements made by vendors on the first day of the RSAC 2026 Conference. SecurityWeek NewsMarch 24, 2026
Vulnerabilities Critical Citrix NetScaler Vulnerability Poised for Exploitation, Security Firms Warn An out-of-bounds read vulnerability can be exploited remotely without authentication to read sensitive information from memory. Ionut ArghireMarch 24, 2026
Malware & Threats Stryker Says Malicious File Found During Probe Into Iran-Linked Attack The FBI has published an alert describing the malware used by Iranian government hackers. Eduard KovacsMarch 24, 2026
Management & Strategy RSAC 2026 Conference Announcements Summary (Pre-Event) A summary of the announcements made by vendors in the days leading up to the RSAC 2026 Conference. SecurityWeek NewsMarch 23, 2026
Cybercrime M-Trends 2026: Initial Access Handoff Shrinks From Hours to 22 Seconds The latest M-Trends report is based on insights from over 500,000 hours of Mandiant incident response investigations in 2025. Eduard KovacsMarch 23, 2026
Phishing Tycoon 2FA Fully Operational Despite Law Enforcement Takedown Attack volumes are back to pre-disruption levels, and the adversary tactics have remained unchanged. Ionut ArghireMarch 23, 2026
Vulnerabilities Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild. Eduard KovacsMarch 23, 2026
Vulnerabilities Critical Quest KACE Vulnerability Potentially Exploited in Attacks The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector. Eduard KovacsMarch 21, 2026
Data Breaches Navia Data Breach Impacts 2.7 Million Between late December 2025 and mid-January 2026, hackers stole personal and health plan information from Navia’s environment. Ionut ArghireMarch 20, 2026
Artificial Intelligence Critical Langflow Vulnerability Exploited Hours After Public Disclosure Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution. Ionut ArghireMarch 20, 2026