
September 27, 2026
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat group used fake news sites and a three-vulnerability Chrome-Windows chain to drop the CLEANGULP backdoor on Asian government targets.

September 27, 2026
Chinese-speaking threat actor exploits WordPress and Zyxel flaws to steal government data
A threat actor linked to Red Heron breached 49 organizations in 29 countries using WordPress wp2shell flaws and a Zyxel switch vulnerability.

September 26, 2026
New Windows Defender zero-day blocks Microsoft antivirus updates
A new proof-of-concept exploit called BigDiskBuster prevents Windows Defender from receiving updates on all supported Windows versions until it stops running.

September 26, 2026
Check Point confirms active exploitation of Security Gateway VPN flaw, ships fixes
Check Point has confirmed attackers are exploiting a pre-auth VPN RCE flaw in Security Gateway, plus a path traversal bug exploited as a zero-day since July.

September 26, 2026
CISA orders federal agencies to patch exploited Zyxel switch flaw by Thursday
CISA adds CVE-2026-7273 to its KEV catalog after GreyNoise documents 996 Zyxel GS1900 switches compromised across 48 countries.

September 26, 2026
SentinelOne extends Wayfinder Threat Hunting coverage to AWS, Azure, and Google Cloud
SentinelOne has expanded Wayfinder Threat Hunting to AWS, Azure, and Google Cloud, adding expert-led cloud control-plane coverage to its endpoint and identity

September 26, 2026
Check Point Patches Critical Management Server Zero-Day Exploited in the Wild
Check Point released urgent patches for a critical 9.8 CVSS directory traversal flaw in Management Server actively exploited in attacks.

September 26, 2026
F5 BIG-IP APM Zero-Day CVE-2026-94127 Under Active Attack
F5 and CISA warn that a critical BIG-IP APM flaw is being exploited in the wild. Affected versions and hotfixes are now available.

September 26, 2026
CISA warns ransomware gangs are now exploiting critical JetBrains TeamCity vulnerability
CISA added a critical JetBrains TeamCity authentication bypass flaw to its Known Exploited Vulnerabilities Catalog after confirming ransomware gangs are
