Saturday , June 20 2026

Alert

Android Security Bulletin April 2026
Critical Android Vuln Allows Zero-Interaction DoS Attacks

Android

Google has shared its Android Security Bulletin for April 2026. It includes important security fixes for the popular mobile system. The update has two parts—the 2026-04-01 and 2026-04-05 patch levels. Together, they fix many problems, from local Denial of Service (DoS) issues to serious flaws in special hardware. The 2026-04-01 …

Read More »

CISA directs feds to fix Fortinet EMS flaw by Friday

CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to protect FortiClient Enterprise Management Server (EMS) systems from a known security issue by Friday. Tracked as CVE-2026-35616, this security flaw was found by the cybersecurity company Defused. Fortinet shared urgent fixes over the weekend to fix the problem. They …

Read More »

Operation TrueChaos (CVE-2026-3502)
Operation ‘TrueChaos’ Targets Southeast Asian Government by 0-Day Exploitation

TrueChaos

A critical security flaw in the TrueConf video call software has been used in real attacks. It is a zero-day threat in a campaign aimed at government organizations in Southeast Asia called TrueChaos. The flaw is traced as CVE-2026-3502 . There is no check for integrity when getting application update …

Read More »

Fortinet FortiClient EMS 0-Day Flaw Actively Exploited

EMS

Fortinet has released an urgent fix after security experts disclosed a zero-day flaw in FortiClient EMS that is being used by hackers. CVE-2026-35616 is an Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Successful attacks do not …

Read More »

ALERT
Patch now! Cisco Patches 9.8 CVSS IMC and SSM Flaws

IMC

Cisco has published updates to fix a security issue in the Integrated Management Controller (IMC). If this flaw is used successfully, a remote attacker without authorization could skip authentication and access the system with higher privileges. The vulnerability, tracked as CVE-2026-20093, carries a CVSS score of 9.8 out of a …

Read More »

ALERT
Critical Fortinet Forticlient and Citrix NetScaler memory flaws now under attack

Threat intelligence company Defused said attackers are now actively exploiting a critical vulnerability in Fortinet’s FortiClient EMS platform. This SQL injection flaw, known as CVE-2026-21643, lets attackers run any code on systems that aren’t fixed. They can do this with simple attacks aimed at the FortiClient EMS web interface using …

Read More »

ALERT
CISA Alerts of F5 BIG-IP Flaw Actively Exploited in Attacks

F5 BIG-IP

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a new flaw in F5 BIG-IP systems to its Known Exploited Vulnerabilities (KEV) list. They warned that this flaw is being used in real-world attacks. The vulnarability, known as CVE-2025-53521, was officially noted on March 27, 2026, and federal agencies must …

Read More »