A critical 24 hours in cybersecurity sees CISA issue an urgent warning for over 86,000 Fortinet devices compromised in the 'FortiBleed' credential leak. Simultaneously, a critical, actively exploited RCE vulnerability (CVE-2026-20253) in Splunk Enterprise has been added to the KEV catalog, mandating immediate patching. Adding to the pressure, Microsoft confirmed a new 'RoguePlanet' zero-day in its Defender antivirus with no patch yet available. Other major incidents include an unpatchable BootROM exploit for Apple A12/A13 chips, a major takedown of the SocGholish botnet, and multiple supply-chain attacks targeting the WordPress ecosystem, highlighting widespread risks from infrastructure to endpoints.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.