ALERT

ACTIVE THREATS: CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline  •  CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline  •  ADT confirms data breach after ShinyHunters leak threat  •  CISA Adds Four Known Exploited Vulnerabilities to Catalog  •  New Pack2TheRoot flaw gives hackers root Linux access      ACTIVE THREATS: CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline  •  CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline  •  ADT confirms data breach after ShinyHunters leak threat  •  CISA Adds Four Known Exploited Vulnerabilities to Catalog  •  New Pack2TheRoot flaw gives hackers root Linux access

🟡Vulnerabilities378 stories

Vulnerabilities

Latest cybersecurity vulnerabilities news, analysis, and intelligence.

🟡VulnerabilitiesCRITICAL

Microsoft's March 2026 Patch Tuesday: 77 Vulnerabilities Addressed, Prioritization Still Paramount

Microsoft's March 2026 Patch Tuesday delivered a comprehensive set of security updates, patching at least 77 vulnerabilities across its Windows operating systems and various software components. While this month brings a welcome absence of actively exploited zero-day flaws, a stark contrast to February's five, cybersecurity teams must still prioritize rapid deployment of critical fixes to safeguard against significant potential risks.

via Krebs on Security·
🟡VulnerabilitiesCRITICAL

Sophisticated Phishing Leverages Bogus VPN Clients to Steal Enterprise Credentials

A cunning new campaign by the threat actor Storm-2561 is distributing highly convincing fake enterprise VPN clients for major vendors like Ivanti, Cisco, and Fortinet. This insidious tactic aims to deceive unsuspecting corporate users into surrendering their legitimate login credentials, providing attackers with a critical foothold into organizational networks for subsequent malicious activities.

via BleepingComputer·