Exchange Server OWA Spoofing Flaw Actively Exploited
Critical Exchange Server spoofing flaw under active attack. CVE-2026-42897 affects on-premise versions with CVSS 8.1. Patch immediately if you’re running 2016/2019.
Critical Exchange Server spoofing flaw under active attack. CVE-2026-42897 affects on-premise versions with CVSS 8.1. Patch immediately if you’re running 2016/2019.
JDownloader’s website was hacked and installer downloads were replaced with malware for days. Millions of users potentially at risk from this supply chain attack.
Ghostwriter APT group strikes again: New campaign targeting Ukrainian government organizations uncovered by ESET researchers. FrostyNeighbor continues its attacks.
Gremlin stealer just leveled up. New variant uses resource file obfuscation, crypto clipping and session hijacking to fly under the radar. Your data’s at risk.
Hackers now hijacking M365 accounts through Outlook calendar invites. The EvilTokens kit lets attackers steal session tokens and bypass MFA entirely.
Microsoft reveals Exchange Server zero-day being actively exploited. Attackers use XSS to execute arbitrary code targeting Outlook on the web. Patch now.
Day Two of Pwn2Own Berlin 2026: $523K awarded for 24 zero-days on Day One. SharePoint, Exchange, and Safari under attack today. The race for Master of Pwn intensifies
CISA adds Cisco SD-WAN authentication bypass to KEV catalog. Critical flaw CVE-2026-20182 exploited for admin access. Federal agencies have until May 2026.
Canvas LMS hacked: cybercriminals claim they deleted stolen student data. Yeah right. Nobody’s buying it except maybe the executives.
Apple’s iOS 26.5 introduces default end-to-end encrypted RCS messaging between iPhone and Android devices, closing a long-standing cross-platform security gap. The update also patches over 50 vulnerabilities across iOS and iPadOS components.