Malawi CERT Urges Immediate MikroTik Router Fixes
- Patch now: Update RouterOS to the latest stable version via admin interface or ISP.
- Restrict access: Block SSH and management interfaces from...

Created by Elhanan Abrams
48‑hour breach, ransomware, zero‑day intel for critical infrastructure and government
Explore the latest content tracked by Cyber Threat Pulse
Texas Mutual Insurance Company notified the Texas AG of a breach affecting 2,065 state residents plus others nationwide, exposing SSNs, medical data,...
Trend Micro's September 10 update introduces detection rules for newly tracked vulnerabilities affecting identity infrastructure, AI/ML platforms, and...
Critical unauthenticated RCE flaws in Check Point VPN products require urgent perimeter action.
Hilltop Bank has begun phased recovery from its cybersecurity incident with targeted service reopenings.
Cisco confirms active exploitation of two FMC vulnerabilities by Sandworm and Qilin operators, requiring urgent exposure validation.
-...
Hackers deploying hundreds of AI agents against PaperCut NG/MF zero-days points to faster, larger-scale exploitation of enterprise print systems, with detection requirements likely shifting for IR teams.
DireWolf claims system access on its extortion site, yet eAssist has not confirmed any data compromise.
ShinyHunters claims to have stolen over 200,000 Florida DMV records—including names, SSNs, and driver’s license data—via a password-reset flaw that...
Four nation-state actors rapidly adopted the BlueMoon Chrome+Windows exploit kit within 12 days of first use on 28 August, shrinking the window for...
Healthcare organizations face growing third-party risks as vendor access expands into clinical workflows, with 30% of breaches now involving external...
Security tool misconfigurations triggered breaches or near-misses at 97% of organizations last year, with firewalls driving 42% of incidents.
-...
Healthcare faces escalating dual-impact attacks: third-party breaches exposing patient data alongside operational disruptions risking care.
-...
Google warns of a new Chrome zero-day bug exploited in attacks.
CVE-2026-45659, a CVSS 8.8 deserialization flaw in on-premises SharePoint Server, is now confirmed in ransomware attacks via CISA's KEV catalog.
-...
Microsoft's record 974-patch release demands targeted IR focus over blanket deployment.
Stadtwerke Landsberg quickly isolated its encrypted IT network, kept essential services online, and launched a forensic probe after the September 1...