Tuesday , September 8 2026

Alert

CISA alerts to cyberattacks affecting U.S. water utilities

water

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers (PLCs) used in water and wastewater systems. The agency’s alert is urgent because hackers affected over 30 local water systems in Minnesota. The attacks began last Sunday and went on until …

Read More »

Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

ASUS router

ASUS has put out important security updates for a serious router flaw. This issue could let remote hackers run any commands on the affected devices. The flaw, known as CVE-2026-13385, affects many ASUS router firmware versions, such as the commonly used 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. The ASUS Product Security Advisory …

Read More »

Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Oracle

Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were probably found by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. Vulnerabilities have been fixed in products like Database …

Read More »

CVE-2026-60137, CVE-2026-63030
Patch immediately! 2 high severity WordPress flaws found

WordPress

The WordPress security team received reports about these flaws: CVE-2026-60137 : A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-63030 : A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber …

Read More »

Windows LegacyHive 0, AWS, Fortinet, TP-LINK multiple flaws got hackers attention

A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges, change admin accounts, and run code with admin rights. The public proof‑of‑concept (PoC) from the MSNightmare GitHub account describes the bug as a “Windows user profile service arbitrary hive load …

Read More »

CVE-2026-53412
Zoom Warns of critical account takeover Flaw via Network Access

network access

Zoom has issued updates for a flaw in the Windows desktop client, known as CVE-2026-53412. This issue may allow an unauthenticated user to conduct an account takeover via network access. This flaw arises from improper input validation and may enable unauthenticated attackers to execute account takeover attacks via network access. …

Read More »