A critical 24-hour period in cybersecurity saw active exploitation of zero-day vulnerabilities in Microsoft Exchange (CVE-2026-42897) and a maximum-severity flaw in Cisco SD-WAN (CVE-2026-20182), forcing urgent mitigation actions. Concurrently, proof-of-concept exploits for two unpatched Windows zero-days, named YellowKey and GreenPlasma, were publicly released, creating significant risk. Nation-state activity continued with Russia's Turla APT upgrading its Kazuar backdoor and Belarus-linked Ghostwriter targeting Ukraine. New threats emerged with the discovery of Rex Ransomware and a critical RCE in the CloudNativePG Kubernetes operator, while AI's role in accelerating attacks was highlighted in the maritime sector.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.