Warning of CISA, Zimbra, SharePoint flaw exploitation. Cisco’s zero-day hit in ransomware attacks

Ravi LakshmananMarch 19, 2026Network security/vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to patch two security flaws affecting Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, saying they are actively being exploited in the wild. The vulnerabilities in question are: CVE-2025-66376 (CVSS Score: 7.2) – A stored cross-site scripting […]

OFAC sanctions North Korean IT worker network for funding weapons of mass destruction program through fake remote jobs

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has sanctioned six individuals and two entities for their involvement in the Democratic People’s Republic of Korea (DPRK) Information Technology (IT) Worker Program, which was designed to defraud U.S. companies and generate illicit proceeds to fund North Korea’s weapons of mass destruction (WMD) program. “The […]

Interlock ransomware exploits Cisco FMC Zero-Day CVE-2026-20131 to gain root access

Ravi LakshmananMarch 18, 2026Network security/ransomware Amazon Threat Intelligence is warning of an active Interlock ransomware campaign that exploits a recently revealed critical security flaw in Cisco Secure Firewall Management Center (FMC) software. The vulnerability in question, CVE-2026-20131 (CVSS score: 10.0), is a case of insecure deserialization of a user-supplied Java byte stream, which allows an […]

Get your threat model right

If the Magecart payload is hidden within the EXIF ​​data of a dynamically loaded third-party favicon, the malicious code never actually touches the repository and repository scanners cannot catch it. If your team employs Claude Code Security for static analysis, this is the exact technical boundary where AI code scanning stops and client-side runtime execution […]

9 critical IP KVM flaws allow unauthenticated root access across 4 vendors

Ravi LakshmananMarch 18, 2026Network security/vulnerabilities Cybersecurity researchers are warning of the risks posed by low-cost IP KVM (Keyboard, Video, Mouse Over Internet Protocol) devices. These devices can potentially give an attacker extensive control over a compromised host. The nine vulnerabilities discovered by Eclypsium span four different products: GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, […]

How Mesh CSMA reveals and blocks attack vectors to Crown Jewel

Today’s security teams have no shortage of tools or data. They are overwhelmed by both. But amid terabytes of alerts, breaches, and misconfigurations, security teams still struggle to understand context. Q: What exposures, misconfigurations, and vulnerabilities chain together to create viable attack vectors for valuable attacks? Even the most mature security team has no easy […]

Bug in Ubuntu CVE-2026-3888 allows attackers to gain root by exploiting systemd cleanup timing

Ravi LakshmananMarch 18, 2026Linux / Endpoint security A high-severity security flaw affecting the default installation of Ubuntu Desktop versions 24.04 and later could be exploited to escalate privileges to the root level. This issue, tracked as CVE-2026-3888 (CVSS score: 7.8), could allow an attacker to gain control of a susceptible system. “This flaw (CVE-2026-3888) allows […]

Apple fixes WebKit vulnerability that allows same-origin policy bypass on iOS and macOS

Ravi LakshmananMarch 18, 2026Vulnerability/Zero-day Apple on Tuesday released the first round of background security improvements to address a security flaw in WebKit that affects iOS, iPadOS, and macOS. The vulnerability, tracked as CVE-2026-20643 (CVSS score: N/A), is described as a cross-origin issue in WebKit’s Navigation API that can be exploited to bypass the same-origin policy […]

Critical flaw in unpatched Telnetd (CVE-2026-32746) enables unauthenticated route RCE over port 23

Ravi LakshmananMarch 18, 2026Vulnerability/Data Protection Cybersecurity researchers have uncovered a critical security flaw affecting the GNU InetUtils Telnet daemon (telnetd). This flaw could be exploited by an unauthenticated, remote attacker to execute arbitrary code with elevated privileges. This vulnerability is tracked as CVE-2026-32746 and has a CVSS score of 9.8 out of 10.0. This is […]

AI flaws in Amazon Bedrock, LangSmith, and SGLang enable data breaches and RCEs

Cybersecurity researchers have detailed a new method for extracting sensitive data from artificial intelligence (AI) code execution environments using Domain Name System (DNS) queries. In a report published Monday, BeyondTrust revealed that Amazon Bedrock AgentCore Code Interpreter’s sandbox mode allows outbound DNS queries that attackers can exploit to enable an interactive shell and bypass network […]