Tuesday , September 29 2026

Alert

Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 actively exploited 0 days

April

Microsoft’s April 2026 security update has fixed 167 flaws in its products. This update includes 2 serious zero-day threats and another flaw that needs urgent attention from organizations. Zero-Day Under Active Exploitation The main flaw this month is CVE-2026-32201, a flaw in Microsoft SharePoint Server that is being actively used …

Read More »

ALERT
Fortinet Patched 11 flaws in it’s multiple products including FortiOS, FortiAnalyzer

5

Fortinet put out a large set of security warnings on April 14, 2026. These warnings cover 11 flaws in different products, with two marked as Critical, two as High, and seven as Medium or Low. The reports impact FortiSandbox, FortiAnalyzer, FortiManager, FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager, urging business admins to …

Read More »

Global “Error524” Smishing Campaign Targeting Bangladesh

Error524

A global smishing scam dubbed “Error524” is hitting many countries, including Bangladesh. BGD e-Gov CIRT said,  this scam uses Phishing-as-a-Service (PhaaS) tools to send SMS messages with harmful links. These links redirect victims to highly convincing phishing websites designed to steal: Personal information Banking credentials Payment card data This campaign …

Read More »

Palo Alto Fixes 3 Security Flaws: Agent Disabling to System Privileges

PAN-OS

Palo Alto Networks has issued important updates to fix 3 different flaws in its security products. These issues affect the Cortex XDR Agent, the Autonomous Digital Experience Manager (ADEM), and Cortex XSOAR/XSIAM platforms. The flaws include ways to skip local protection and access resources without permission. The first flaw, known …

Read More »

IBM Identity and Verify Access Vulns Allow to Access Sensitive Data

Verify Access

A security bulletin alert points out several flaws in IMB Verify Identity Access and Security Verify Access products. Tracked as CVE-2026-2862 and CVE-2026-1491, these flaws in HTTP request smuggling come from problems with reverse proxy management and have a CVSS score of 5.3. A remote attacker who is not logged in …

Read More »

Android Security Bulletin April 2026
Critical Android Vuln Allows Zero-Interaction DoS Attacks

Android

Google has shared its Android Security Bulletin for April 2026. It includes important security fixes for the popular mobile system. The update has two parts—the 2026-04-01 and 2026-04-05 patch levels. Together, they fix many problems, from local Denial of Service (DoS) issues to serious flaws in special hardware. The 2026-04-01 …

Read More »