Apple blocked over $11 billion in App Store fraud in 6 years
Apple blocked $11 billion in App Store fraud over six years, including $2.2 billion in 2025. Defense measures rejected 2 million apps and terminated 193,000 fraudulent developer accounts.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity vulnerabilities news, analysis, and intelligence.
Apple blocked $11 billion in App Store fraud over six years, including $2.2 billion in 2025. Defense measures rejected 2 million apps and terminated 193,000 fraudulent developer accounts.
Cisco Secure Workload's CVSS 10.0 vulnerability enables Site Admin escalation. Attackers can bypass authentication, compromise network segmentation, and establish infrastructure backdoors.
Ocean raised $28M for AI agents to combat AI-generated email attacks. As attackers use advanced techniques like business email compromise, the startup's solution provides intelligent analysis beyond traditional filtering.
Cisco patched CVE-2026-20223, a 10.0 CVSS authentication bypass in Secure Workload enabling unauthenticated attackers to escalate to Site Admin and access cross-tenant data. No active exploitation reported.
Two Windows Defender vulnerabilities are actively exploited: CVE-2026-41091 escalates privileges to SYSTEM, while CVE-2026-45498 disables protection. Both are weaponized in real attacks affecting billions of endpoints worldwide.
**Summary:** 48,000 CVEs in 2025 are being exploited an average of 7 days *before* patches exist, making traditional patch-management obsolete. Supply chain visibility gaps and exploitation velocity have created an impossible defense paradox where vulnerabilities spread faster than organizations ca
CVE-2026-46333, a 9-year-old Linux kernel flaw, allows unprivileged users to gain root access or extract SSH keys and password hashes. Affects Debian, Fedora, and Ubuntu through reliable exploits targeting utilities like ssh-keysign and pkexec.
A critical SQL injection in Drupal Core (CVE-2026-9082) allows unauthenticated attackers to execute arbitrary SQL on PostgreSQL databases, risking data theft and remote code execution.
250+ Android apps disguised as popular apps silently enroll users in carrier-billed services across Asia-Europe. Malware intercepts OTPs to bypass security in a 10-month billing fraud campaign.
Survey of 16,000 security pros reveals AI's paradox: widely seen as cybersecurity's best defense, yet 52% view it as the industry's biggest threat, fearing AI-powered attacks and agentic systems.
Attackers exploit CVE-2024-12802 in SonicWall Gen6 VPN devices to bypass MFA and access enterprise networks. Firmware patches alone won't stop them—manual remediation is required.
Quantum Bridge raised $8M to deploy quantum-safe cryptography as enterprises rush to defend against harvest-now-decrypt-later attacks. Adversaries are collecting encrypted data today to decrypt once quantum computers mature, making immediate cryptographic upgrades critical for protecting sensitive i
Microsoft patched CVE-2026-45585 ('YellowKey'), a BitLocker bypass letting attackers circumvent full-disk encryption via USB. It exploits WinRE startup, affecting even TPM-protected systems.
PolyScope 5's Dashboard Server contains a critical command injection flaw (CVE-2026-8153) allowing unauthenticated remote code execution on cobot controllers with no user interaction needed. Affects collaborative robots globally across manufacturing, automotive, and healthcare facilities.
Enterprises deploy AI systems to production without security involvement, creating blind spots for model poisoning and prompt injection threats. Security teams lack governance frameworks to defend against AI's unique attack surfaces, repeating the same pattern seen with cloud and container adoption.
Anthropic quietly patched a SOCKS5 null-byte injection in Claude Code's sandbox without public disclosure. The flaw bypassed network restrictions and enabled data exfiltration via crafted hostnames exploiting filtering gaps.
AI BOMs provide transparency into model components and training data. CISOs must actively shape their creation to close the gap between regulatory demands and reality.
Drupal patched a critical vulnerability with high exploitation risk, affecting ~1 million sites globally. The security team warns attackers will likely weaponize it within hours of patch disclosure.
**YellowKey (CVE-2026-45585) critically bypasses BitLocker on Windows 11/Server 2025 via physical access.** Attackers craft malicious files to boot into WinRE and access encrypted volumes in minutes. The public PoC creates immediate risk for enterprises relying on BitLocker as their primary endpoint
A public exploit for PinTheft, a Linux privilege escalation flaw, has been released by V12 security. Exploitable by local users on RDS-enabled systems (primarily Arch Linux), it enables root access and persistent compromise.
Operation Ramz unites 13 MENA nations in coordinated cybercrime enforcement. Though arrests were modest, the collaboration signals newfound institutional maturity against cross-border networks.
AI models lack supply chain transparency—components, datasets, and dependencies stay hidden from deployers. Industry is standardizing AI Bills of Materials (BOMs) to document model internals and manage risk.
Vulnerability exploitation (31%) now leads credential abuse (13%) as Verizon's top breach vector. AI is compressing exploit timelines from months to hours, outpacing patch efforts.
"'Nightmare Eclipse' disclosed six Windows vulnerabilities in six weeks; three are actively exploited. Flaws affect encryption and privilege escalation across Windows systems, with CISA tracking known exploits."
Verizon's 2026 DBIR reveals a critical patching crisis: exploits now cause 31% of breaches while only 26% of critical vulnerabilities get remediated (down from 38% in 2024). With patch resolution times hitting 43 days and vulnerability volumes surging 50%, defenders are dangerously falling behind at
**ChromaDB vector database has a critical vulnerability (CVE-2026-45829) allowing unauthenticated attackers to execute code by forcing malicious ML models to load. The widely-adopted platform powering AI applications remained unfixed three months after disclosure on February 17, 2026.**
ZKTeco CCTV cameras leak admin credentials through an undocumented backdoor port requiring no authentication, exposing global enterprises to remote compromise. CVE-2026-8598 (CVSS 9.1 CRITICAL) affects SSC335-GC2063-Face models—update to firmware V5.0.1.2.20260421 immediately.
ScadaBR's four vulnerabilities enable unauthenticated attackers to execute arbitrary commands on critical infrastructure. Vendor refused patches, exposing power grids, water systems, and more globally.
ABB's CoreSense monitoring systems have a critical path traversal flaw (CVE-2025-3465) allowing local attackers unauthorized file access without authentication. The CVSS 7.1 vulnerability threatens critical infrastructure in manufacturing, agriculture, and food sectors by exposing sensitive configs,
XSS vulnerability CVE-2026-4293 affects Kieback & Peter building controllers used in critical infrastructure. It allows attackers to inject malicious code into HVAC, security, and access systems across hospitals, data centers, and government facilities.