Netlogon CVE-2026-41089 RCE
CVE-2026-41089 is now reported as actively exploited. Patch Windows Server domain controllers and review Netlogon, LSASS, and authentication logs.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 4, 2026
CVE-2026-41089 is now reported as actively exploited. Patch Windows Server domain controllers and review Netlogon, LSASS, and authentication logs.
FortiClient EMS CVE-2026-35616 was abused to push EKZ Infostealer as a fake patch. Check EMS logs, managed endpoints, browser credentials, and hotfixes.
CISA added PAN-OS CVE-2026-0257 to KEV after exploitation. Check GlobalProtect portals and gateways, patch PAN-OS, and disable unsafe authentication override cookies.
Rapid7 disclosed a critical unpatched Gogs RCE path. Check open registration, repository creation, and rebase merge settings now.
sysupdate.jpeg malware is a fake image loader tied to Operation SilentCanvas. Learn what to check, how ScreenConnect is abused, and how to clean Windows…
Downloaded CPU-Z or HWMonitor during the CPUID compromise? Check the April 9-10 window, CRYPTBASE.dll, browser passwords, and clean up safely.
TrapDoor spreads malicious packages through npm, PyPI and Crates.io, steals developer secrets, and hides instructions in CLAUDE.md and .cursorrules.
Megalodon injected malicious GitHub Actions workflows into 5,561 repositories. Here is what maintainers should audit before rotating secrets and publishing packages.
DenoRAT is a Deno-based RAT and stealer delivered through ClickFix, DinDoor, and fake downloads. Learn the attack chain, warning signs, and recovery steps.