Microsoft says Star Blizzard uses RedFlick to deploy CosmicPulse
Microsoft says the Russian state actor shifted to mass phishing and a one-click malware delivery technique, affecting more than 100 organizations, mostly in the US and UK.

Microsoft says the Russian state actor shifted to mass phishing and a one-click malware delivery technique, affecting more than 100 organizations, mostly in the US and UK.

Two vulnerabilities in the cellular gateway's update mechanism could let attackers run code with root privileges, CISA said, with fixed firmware available from Lantronix.

CISA says the worst of the nine vulnerabilities scores 9.8 and could give an attacker full control of the device, and that the vendor has not responded.

CISA added the Apple Multiple Products vulnerability to its Known Exploited Vulnerabilities catalog on September 29, 2026, with a federal remediation deadline of October 2, 2026.

CISA said threat actors are exploiting two critical NetScaler ADC and Gateway flaws globally, among eight vulnerabilities disclosed by Citrix.

CISA added the MikroTik RouterOS vulnerability to its Known Exploited Vulnerabilities catalog on September 25, 2026, with a federal remediation deadline of September 28, 2026.

CISA added the Microsoft SharePoint vulnerability to its Known Exploited Vulnerabilities catalog on September 25, 2026, with a federal remediation deadline of September 28, 2026.

CISA added the WordPress Core vulnerability to its Known Exploited Vulnerabilities catalog on September 25, 2026, with a federal remediation deadline of September 28, 2026.
We use cookies to measure readership and, with your permission, to show relevant TechUpscale ads on other sites. We honor Global Privacy Control. You can change your choice any time under "Cookie settings" at the bottom of every page. Privacy policy