Storm-1175 Debuts New Ransomware
Microsoft says China-linked Storm-1175 shifts from Medusa to the new StormEncryptor ransomware, likely via N-central flaw CVE-2026-18577.
30 results for “2026”
Microsoft says China-linked Storm-1175 shifts from Medusa to the new StormEncryptor ransomware, likely via N-central flaw CVE-2026-18577.
Microsoft tracks Storm-1175's shift to StormEncryptor, following exploitation of an N-central flaw.
CISA warns of active exploitation of critical command injection flaw in Progress Kemp LoadMaster; urges patching.
Australia's 2026 Census is compulsory, with new questions and a AU$364 daily fine for non-compliance.
A critical command injection vulnerability in the MSI RadiX AXE6600 router allows remote attackers to execute arbitrary code and gain root access.
A critical vulnerability in the MSI Radix AXE6600 router allows remote attackers to gain root access via the wps.cgi interface.
A critical buffer overflow vulnerability in the D-Link DWR-M961 allows remote attackers to execute arbitrary code or crash the device.
Dell has issued an urgent update for its Virtual Storage Integrator to fix a critical vulnerability that allows unauthenticated attackers to hijack sessions.
A critical authorization bypass in the AI Copilot plugin allows unauthenticated attackers to create administrator accounts and seize full control of websites.
A critical authentication vulnerability in Dell OpenManage Server Administrator allows unauthenticated remote attackers to gain unauthorized access.
A high-severity vulnerability in Azure SQL Managed Instance allows unauthorized network-based privilege escalation, requiring immediate attention.
A critical vulnerability in CodeIgniter 4 allows attackers to bypass file validation, potentially leading to remote code execution on affected servers.
A critical command injection vulnerability in Progress LoadMaster is under active exploitation, prompting urgent CISA remediation requirements.
Recent investigations reveal how attackers leverage legitimate accounts and blockchain data to execute sophisticated financial fraud.
A critical authorization bypass in the Paperclip platform allowed attackers to execute arbitrary code with server-level permissions.
New data indicates a sharp rise in ransomware incidents throughout July 2026, breaking a multi-month period of lower activity.
A critical authorization bypass vulnerability in the TrueBooker plugin allows unauthenticated attackers to reset passwords for any user, including administrators.
A critical server-side request forgery vulnerability in Microsoft Office SharePoint allows unauthorized network spoofing and carries a CVSS score of 9.6.
A critical authorization vulnerability in the Azure SRE Agent allows attackers to escalate privileges over a network, warranting immediate attention.
A critical authorization vulnerability in Microsoft Power Apps allows remote attackers to elevate privileges, necessitating immediate attention from administrators.
A high-severity vulnerability in Azure Active Directory allows authorized attackers to perform privilege escalation across the network.
A critical privilege escalation vulnerability in the Microsoft Entra Provisioning Service allows authorized attackers to gain elevated network access.
A critical authentication bypass in Azure SQL Database allows unauthorized attackers to gain elevated privileges over a network.
A critical vulnerability in Azure Logic Apps allows unauthorized information disclosure, earning a CVSS score of 9.6.
A critical flaw in IBM's Langflow platform is currently being exploited, prompting an urgent warning from federal security officials.
A high-severity cryptographic key derivation vulnerability in IBM Langflow OSS could allow unauthorized access to sensitive data.
A cryptographic weakness in IBM Langflow OSS allows attackers to reproduce encryption keys, potentially exposing stored API keys and authentication tokens.
A deserialization vulnerability in JetBrains TeamCity is under active exploitation, forcing federal agencies to patch systems by August 8, 2026.
A critical SQL injection vulnerability in Loca Software CMS allows unauthorized attackers to gain full control over affected database systems.
New data reveals a surge in violent physical thefts targeting cryptocurrency holders, with millions lost in the first half of 2026.