Cybersecurity

Cyberattacks, vulnerabilities, data breaches, ransomware, threat intelligence and security responses.

  1. WordPress released version 7.0.2 on July 17, 2026, to address a critical vulnerability allowing remote code execution, according to security reports.

  2. A tool released on September 21, 2026, prevents updates for Microsoft Defender Antivirus, according to reports. No patch has been issued.

  3. Group-IB reported RemControl, an Android malware targeting users in Europe, Canada, and the Middle East through fraudulent Google Play apps.

  4. F5 issued a security advisory on September 22, 2026, confirming active exploitation of a critical BIG-IP vulnerability allowing remote code execution.

  5. A ransomware attack on GPAA systems accessed 168,000 records. Full restoration was completed by June 21, 2024, according to agency statements.

  6. Check Point issued emergency hotfixes on September 22, 2026, for a critical vulnerability (CVE-2026-93616) affecting its Management Server.

  7. KISA is enhancing national cybersecurity through AI and big data for vulnerability management, promoting security product commercialization, according to reports.

  8. A filing describes the Cyber Security and Resilience Bill introduced in November 2025, according to official documents. It mandates 24-hour reporting.

  9. CISA added three high-risk Linux kernel vulnerabilities to its KEV catalog. Agencies must patch these flaws by September 21, 2026, according to reports.

  10. A statement details a data breach involving Ribon app credentials, according to reports. Customer data was accessed from merchant storefronts.

  11. A Ukrainian ransomware developer received a 12-year sentence, according to court documents. A vulnerability related to Plugin4Shell was also disclosed.

  12. AI agents have breached systems like Hugging Face, highlighting security flaws in frameworks, according to researchers. Vulnerabilities were automated.

  13. Manufacturers must report cybersecurity incidents starting September 2026, according to the Cyber Resilience Act and ENISA's Single Reporting Platform.

  14. Microsoft's ransomware guidance stresses that boards must address vulnerabilities throughout the entire attack process, according to reports.

  15. Manufacturing represented 22% of ransomware victims in 2026, with attacks increasing nearly 40%, according to published data.

  16. A vulnerability in the WooCommerce Wholesale Lead Capture plugin allowed file uploads. Over 100,000 exploitation attempts were blocked, according to Wordfence.

  17. Zimperium's zLabs discovered RatHat, an AI-driven Android malware that captures credentials and prevents removal, according to security researchers.

  18. A report outlines token security recommendations, including key management, issued by the regulator on September 15, 2026, according to the agency.

  19. KREMLIN malware targets Brazilian banks by installing unauthorized browser extensions on over 1,500 systems, according to Elastic Security Labs.

  20. Two vulnerabilities in TP-Link Tapo C200 cameras were patched with firmware update V5_1.4.6 on August 18, 2026, according to company reports.