Thursday , July 30 2026

Alert

CISA directs feds to fix Fortinet EMS flaw by Friday

CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to protect FortiClient Enterprise Management Server (EMS) systems from a known security issue by Friday. Tracked as CVE-2026-35616, this security flaw was found by the cybersecurity company Defused. Fortinet shared urgent fixes over the weekend to fix the problem. They …

Read More »

Operation TrueChaos (CVE-2026-3502)
Operation ‘TrueChaos’ Targets Southeast Asian Government by 0-Day Exploitation

TrueChaos

A critical security flaw in the TrueConf video call software has been used in real attacks. It is a zero-day threat in a campaign aimed at government organizations in Southeast Asia called TrueChaos. The flaw is traced as CVE-2026-3502 . There is no check for integrity when getting application update …

Read More »

Fortinet FortiClient EMS 0-Day Flaw Actively Exploited

EMS

Fortinet has released an urgent fix after security experts disclosed a zero-day flaw in FortiClient EMS that is being used by hackers. CVE-2026-35616 is an Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Successful attacks do not …

Read More »

ALERT
Patch now! Cisco Patches 9.8 CVSS IMC and SSM Flaws

IMC

Cisco has published updates to fix a security issue in the Integrated Management Controller (IMC). If this flaw is used successfully, a remote attacker without authorization could skip authentication and access the system with higher privileges. The vulnerability, tracked as CVE-2026-20093, carries a CVSS score of 9.8 out of a …

Read More »

ALERT
Critical Fortinet Forticlient and Citrix NetScaler memory flaws now under attack

Threat intelligence company Defused said attackers are now actively exploiting a critical vulnerability in Fortinet’s FortiClient EMS platform. This SQL injection flaw, known as CVE-2026-21643, lets attackers run any code on systems that aren’t fixed. They can do this with simple attacks aimed at the FortiClient EMS web interface using …

Read More »

ALERT
CISA Alerts of F5 BIG-IP Flaw Actively Exploited in Attacks

F5 BIG-IP

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a new flaw in F5 BIG-IP systems to its Known Exploited Vulnerabilities (KEV) list. They warned that this flaw is being used in real-world attacks. The vulnarability, known as CVE-2025-53521, was officially noted on March 27, 2026, and federal agencies must …

Read More »

270M iPhones Vulnerable to ‘DarkSword’ Exploit
270m iPhones Vulnerable to ‘DarkSword’ Exploit: Hack code now on GitHub

iPhone

The iPhone is said as one of the safest smartphones now, but like Android phones, it has been attacked by hackers who use various flaws. Last week, a cybersecurity expert found a hacking scheme aimed at iPhone users using a tool named DarkSword. Now, someone has uploaded a new version of …

Read More »