Kiteworks Patches Critical Advanced Forms Vulnerability After Emergency Shutdown
Kiteworks fixed a previously unknown critical vulnerability in Advanced Forms after a precautionary shutdown and says it found no evidence of exploitation.
Read itA3E Cyber Blog
Daily cybersecurity news, breach analysis, practical guidance, and security updates written for business owners.
Kiteworks fixed a previously unknown critical vulnerability in Advanced Forms after a precautionary shutdown and says it found no evidence of exploitation.
Read itApple patched CVE-2026-86950, a CoreGraphics zero-day that can enable arbitrary code execution when a device processes a maliciously crafted file.
Read itTimes Car confirmed that attackers obtained data tied to approximately 6.6 million current and former accounts, including contact details and some identity documents.
Read itBitget confirmed approximately $387.5 million was transferred to attacker-controlled addresses in a hot and warm wallet breach and has begun restoring withdrawals.
Read itCloudflare fixed a Containers isolation flaw that could expose residual disk data across customer accounts. The company found no evidence of malicious exploitation.
Read itCitrix has confirmed active exploitation of two critical NetScaler ADC and Gateway zero-days, CVE-2026-88771 and CVE-2026-88772. Patches are available and affected organizations should update immediately and check for compromise.
Read itCISA has added critical WSO2 vulnerability CVE-2026-5430 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Organizations running affected WSO2 API products should apply vendor fixes immediately and review exposed systems for signs of compromise.
Read itAstrana Health disclosed a material cybersecurity incident after attackers impersonated company personnel, spoofed its corporate phone number, and gained unauthorized access to systems. The company says private or confidential data was accessed or acquired.
Read itCISA has updated its warning for CVE-2026-63077 to indicate the critical JetBrains TeamCity vulnerability is now being used in ransomware campaigns. The flaw can let an unauthenticated attacker execute operating-system commands on vulnerable TeamCity On-Premises servers.
Read itCheck Point has confirmed active exploitation of CVE-2026-85102, a critical pre-authentication remote code execution flaw affecting Security Gateway and Spark Firewall VPN deployments. Organizations using affected products should verify fixes and review for suspicious activity.
Read it