Security news, decoded.
74 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.
The wire
Thursday, May 146 stories
- Cisco TalosOngoing exploitation of Cisco Catalyst SD-WAN vulnerabilitiesReported exploitedCisco Catalyst SD-WAN Controller (vSmart)
- Rapid7 BlogCVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)PatchCisco Catalyst SD-WAN Controller (vSmart)
- Rapid7 BlogWhen Network Controllers Become "God Mode" for AttackersReported exploitedCisco Catalyst SD-WAN Controller
- Bishop FoxOtto Support - Logging and Visibility in MCP ServersResearchModel Context Protocol (MCP)
- ESET WeLiveSecurityFrostyNeighbor: Fresh mischief and digital shenanigansReported exploitedPicassoLoader
- Risky Business News
Wednesday, May 133 stories
- Rapid7 BlogPluribus and the Path to Domain Compromise: A ModeloRAT Case StudyReported exploitedModeloRAT
- Check Point ResearchThus Spoke…The GentlemenIncidentRocket
- Google Project ZeroA 0-click exploit chain for the Pixel 10: When a Door Closes, a Window OpensPoC publicGoogle Pixel
Tuesday, May 123 stories
- Krebs on SecurityPatch Tuesday, May 2026 EditionRoundupWindows
- Cisco Talos
- Qualys Security Blog
Monday, May 114 stories
- Ars Technica (Security)Linux bitten by second severe vulnerability in as many weeksReported exploitedLinux kernel
- Check Point Research11th May – Threat Intelligence ReportRoundupMOVEit Automation
- Check Point ResearchThe State of Ransomware – Q1 2026RoundupQilin
- Palo Alto Unit 42Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and ToolsReported exploitedActive Directory Certificate Services (AD CS)
Thursday, May 71 story
- Bishop FoxOtto Support - SSRF and Token Passthrough with MCPResearchmcp-atlassian
Wednesday, May 63 stories
- Bishop FoxCVE-2026-42208: Pre-Authentication SQL Injection in LiteLLM ProxyReported exploitedLiteLLM Proxy
- Dark Reading
- Palo Alto Unit 42
Tuesday, May 51 story
- Palo Alto Unit 42Copy Fail: What You Need to Know About the Most Severe Linux Threat in YearsPoC publicLinux kernel (AF_ALG/algif_aead)
Monday, May 41 story
- Check Point Research4th May – Threat Intelligence ReportRoundupShinyHunters
Thursday, Apr 301 story
- Krebs on SecurityAnti-DDoS Firm Heaped Attacks on Brazilian ISPsReported exploitedArcher AX21 routers
Wednesday, Apr 291 story
- watchTowr LabsThe Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)Reported exploitedcPanel & WHM
Tuesday, Apr 281 story
- GitHub Security Lab
Monday, Apr 271 story
- Check Point Research27th April – Threat Intelligence ReportRoundupContext.ai (OAuth token access)
Thursday, Apr 231 story
- Bishop FoxOtto Support – An MCP, Agentic-AI Security ChallengeResearchotto-support CTF
Monday, Apr 201 story
- Check Point Research20th April – Threat Intelligence ReportReported exploitedApache ActiveMQ
Thursday, Apr 161 story
- ESET WeLiveSecurity
Tuesday, Apr 142 stories
- Krebs on SecurityPatch Tuesday, April 2026 EditionReported exploitedWindows
- GitHub Security LabHack the AI agent: Build agentic AI security skills with the GitHub Secure Code GameResearchGitHub Secure Code Game
Monday, Apr 131 story
- Check Point Research13th April – Threat Intelligence ReportReported exploitedBitcoin Depot wallets/crypto-ATM systems
Tuesday, Apr 72 stories
- Bishop FoxAPI Authentication Bypass in FortiClient EMS 7.4.5-7.4.6–CVE-2026-35616Reported exploitedFortiClient EMS
- NCSC UKAPT28 exploit routers to enable DNS hijacking operationsReported exploitedTP-Link WR841N
Thursday, Apr 22 stories
- watchTowr LabsYou’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)ResearchProgress ShareFile Storage Zone Controller
- MandiantvSphere and BRICKSTORM Malware: A Defender's GuideResearchVMware vCenter Server Appliance (VCSA)
Sunday, Mar 291 story
- watchTowr LabsPlease, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)Reported exploitedNetScaler ADC
Saturday, Mar 281 story
Thursday, Mar 261 story
- Bishop FoxstrongSwan CVE-2026-25075: Integer Underflow in VPN AuthenticationPoC publicstrongSwan