Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could let users and servers face cross-site scripting, email header issues, data access from other users, remote content tricks, and attacks that misuse server requests. The new versions, Roundcube 1.6.19 and …
Read More »ALERT
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access
Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take full control without logging in, as per CERT Polska’s warning released on September 5. Successful attacks started on at least September 2. The Hacker News review on September 6 found …
Read More »14,000 Dahua cameras compromised: TP-Link flaws enable RCE
Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices around the world. This shows the rising danger of unsafe and unprotected surveillance systems. Researchers at Hunt.io found the operation by looking into a public directory with 2,616 files related …
Read More »Google issues warning of new Chrome zero-day flaw exploited
Google has updated the Chrome browser to fix a serious security issue in the V8 engine and 11 other flaws. The security flaw, called CVE-2026-85046, is a type confusion. Researcher Salvatore Gulizia, known as “Serotav,” told Google about it. The update makes Chrome version 152.0.7977.82/.83 for Windows and macOS, and …
Read More »SonicWall SMA1000 SSRF Hits 10, Exploiting CVE-2026-83548
SonicWall unveiled advisory SNWLID-2026-0016 on September 1, 2026. It states that two SMA1000 flaws are being actively exploited. The main issue, CVE-2026-83548, is a pre-authentication SSRF with a top score of 10.0 CVSS. The second issue, CVE-2026-83549, allows remote code execution after authentication. Why It Matters SMA1000 devices act as …
Read More »
CVE-2026-62911
Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack
Almost 22,000 Microsoft Exchange servers are online and still vulnerable to a flaw that lets attackers access all user mailboxes. Tracked as CVE-2026-62911 and reported by Orange Tsai from DEVCORE Research Team, this security flaw impacts Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. “Authentication bypass …
Read More »CISA alerts on multiple PaperCut NG/MF flaws being actively exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed two flaws in PaperCut NG and PaperCut MF in its Known Exploited Vulnerabilities (KEV) Catalog. They warn that hackers are using these flaws in real attacks. The flaws with PaperCut, known as CVE-2026-81578 and CVE-2026-82078, can be linked together. This …
Read More »Fire Ant hackers convert Cisco routers into spy platforms
The researchers discovered Fire Ant’s new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. According to incident response company Sygnia, The threat actor moved from attacking VMware hypervisors to breaking …
Read More »Five Critical WordPress Flaws Lead to Site Takeover or RCE
Many serious security flaws have been found in WordPress plugins and themes, such as WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These issues could let hackers bypass login, take over accounts, and run any code. The vulnerabilities, according to Wordfence and Patchstack, are listed below: CVE-2026-76581 (CVSS score: 9.8): …
Read More »ServiceNow warns of three critical security vulnerabilities
ServiceNow issued security updates for three new serious AI Platform problems that can be used in code injection, SQL injection, and privilege escalation attacks. The ServiceNow AI Platform, which was once called the Now Platform, is a strong Platform-as-a-Service (PaaS). It helps add AI to important business tasks and supports …
Read More »
InfoSecBulletin Cybersecurity for mankind