A critical, actively exploited RCE vulnerability (CVE-2026-24423) in SmarterMail has been added to CISA's KEV catalog, fueling ransomware attacks. Concurrently, a major ransomware incident has crippled the BridgePay payment gateway, causing nationwide outages for merchants. Other significant developments in the past 24 hours include CISA mandating the removal of unsupported edge devices from federal networks, attribution of a Notepad++ supply chain attack to a Chinese APT, and the discovery of a new EDR-killing malware that abuses a decade-old driver.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.