<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Updates only</title>
    <link>https://cyber.netsecops.io/</link>
    <description>20 Recently updated articles</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 04 Sep 2026 16:34:53 GMT</lastBuildDate>
    <atom:link href="https://cyber.netsecops.io/rss/updates.xml" rel="self" type="application/rss+xml"/>

    <item>
      <title>[UPDATED] CISA: Over 100 U.S. Water Systems Targeted in July Cyber Campaign</title>
      <link>https://cyber.netsecops.io/articles/over-100-us-water-systems-targeted-in-widespread-cyber-campaign/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/over-100-us-water-systems-targeted-in-widespread-cyber-campaign/</guid>
      <pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that a widespread cyber campaign in July 2026 targeted over 100 systems in the U.S. Water and Wastewater Systems (WWS) sector. The attacks, widely attributed to Iranian state-aligned actors, exploited internet-exposed indu...</p><p><strong>Severity:</strong> Critical</p><p><strong>Categories:</strong> Industrial Control Systems, Cyberattack, Threat Actor</p><p><a href="https://cyber.netsecops.io/articles/over-100-us-water-systems-targeted-in-widespread-cyber-campaign/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/over-100-us-water-systems-targeted-in-widespread-cyber-campaign.jpg" type="image/jpeg" length="0"/>
      <category>Industrial Control Systems</category>
      <category>Cyberattack</category>
      <category>Threat Actor</category>
    </item>

    <item>
      <title>[UPDATED] CISA Adds Seven Actively Exploited Flaws to KEV Catalog</title>
      <link>https://cyber.netsecops.io/articles/cisa-adds-seven-actively-exploited-vulnerabilities-to-kev-catalog/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/cisa-adds-seven-actively-exploited-vulnerabilities-to-kev-catalog/</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list includes critical flaws in SonicWall, Kestra, and JFrog products. This action falls under the new Bi...</p><p><strong>Severity:</strong> Critical</p><p><strong>Categories:</strong> Vulnerability, Patch Management, Threat Intelligence</p><p><a href="https://cyber.netsecops.io/articles/cisa-adds-seven-actively-exploited-vulnerabilities-to-kev-catalog/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/cisa-adds-seven-actively-exploited-vulnerabilities-to-kev-catalog.jpg" type="image/jpeg" length="0"/>
      <category>Vulnerability</category>
      <category>Patch Management</category>
      <category>Threat Intelligence</category>
    </item>

    <item>
      <title>[UPDATED] SonicWall Patches Two Actively Exploited SMA 1000 Zero-Days</title>
      <link>https://cyber.netsecops.io/articles/sonicwall-urges-patching-for-two-actively-exploited-zero-day-vulnerabilities/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/sonicwall-urges-patching-for-two-actively-exploited-zero-day-vulnerabilities/</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>SonicWall has released urgent security patches for two zero-day vulnerabilities in its SMA 1000 series appliances. The flaws, a critical-rated server-side request forgery (SSRF) and a high-severity command injection, are being actively chained by attackers to achieve unauthenticated remote code exec...</p><p><strong>Severity:</strong> Critical</p><p><strong>Categories:</strong> Vulnerability, Cyberattack, Patch Management</p><p><a href="https://cyber.netsecops.io/articles/sonicwall-urges-patching-for-two-actively-exploited-zero-day-vulnerabilities/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/sonicwall-urges-patching-for-two-actively-exploited-zero-day-vulnerabilities.jpg" type="image/jpeg" length="0"/>
      <category>Vulnerability</category>
      <category>Cyberattack</category>
      <category>Patch Management</category>
    </item>

    <item>
      <title>[UPDATED] PaperCut Zero-Day RCE Actively Exploited; Emergency Patches Released</title>
      <link>https://cyber.netsecops.io/articles/papercut-warns-of-actively-exploited-zero-day-rce-vulnerability/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/papercut-warns-of-actively-exploited-zero-day-rce-vulnerability/</guid>
      <pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>Print management software provider PaperCut has issued an urgent security warning about a vulnerability chain being actively exploited in the wild. The flaws, affecting all versions of PaperCut NG and MF, can be chained to achieve pre-authentication remote code execution (RCE). The attack combines a...</p><p><strong>Severity:</strong> Critical</p><p><strong>Categories:</strong> Vulnerability, Patch Management, Cyberattack</p><p><a href="https://cyber.netsecops.io/articles/papercut-warns-of-actively-exploited-zero-day-rce-vulnerability/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/papercut-warns-of-actively-exploited-zero-day-rce-vulnerability.jpg" type="image/jpeg" length="0"/>
      <category>Vulnerability</category>
      <category>Patch Management</category>
      <category>Cyberattack</category>
    </item>

    <item>
      <title>[UPDATED] SonicWall Warns of Two Actively Exploited Zero-Days in SMA1000</title>
      <link>https://cyber.netsecops.io/articles/sonicwall-sma1000-zero-day-vulnerabilities-actively-exploited/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/sonicwall-sma1000-zero-day-vulnerabilities-actively-exploited/</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>SonicWall has issued urgent patches for two zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, affecting its SMA 1000 series appliances. The flaws, a critical server-side request forgery (SSRF) and a command injection, are being actively chained by threat actors to achieve unauthenticated ...</p><p><strong>Severity:</strong> Critical</p><p><strong>Categories:</strong> Vulnerability, Cyberattack, Patch Management</p><p><a href="https://cyber.netsecops.io/articles/sonicwall-sma1000-zero-day-vulnerabilities-actively-exploited/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/sonicwall-sma1000-zero-day-vulnerabilities-actively-exploited.jpg" type="image/jpeg" length="0"/>
      <category>Vulnerability</category>
      <category>Cyberattack</category>
      <category>Patch Management</category>
    </item>

    <item>
      <title>[UPDATED] Google Patches Two Critical Use-After-Free Flaws in Chrome</title>
      <link>https://cyber.netsecops.io/articles/google-patches-critical-use-after-free-vulnerabilities-in-chrome/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/google-patches-critical-use-after-free-vulnerabilities-in-chrome/</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>Google has released a security update for its Chrome browser, version 152.0.7977.75 for Windows/Mac and 152.0.7977.76 for Linux, addressing 26 vulnerabilities. The patch includes fixes for two critical use-after-free flaws, CVE-2026-84353 in Shared Tab Groups and CVE-2026-84352 in WebGL. These vulne...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Vulnerability, Patch Management</p><p><a href="https://cyber.netsecops.io/articles/google-patches-critical-use-after-free-vulnerabilities-in-chrome/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/google-patches-critical-use-after-free-vulnerabilities-in-chrome.jpg" type="image/jpeg" length="0"/>
      <category>Vulnerability</category>
      <category>Patch Management</category>
    </item>

    <item>
      <title>[UPDATED] EU Cyber Resilience Act's 24-Hour Reporting Mandate Starts Sept 11</title>
      <link>https://cyber.netsecops.io/articles/eu-cyber-resilience-act-mandatory-reporting-deadline-approaches/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/eu-cyber-resilience-act-mandatory-reporting-deadline-approaches/</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>Manufacturers of connected products sold in the EU must comply with the Cyber Resilience Act's (CRA) new reporting obligations starting September 11, 2026. The rules mandate reporting actively exploited vulnerabilities and severe incidents affecting their products to ENISA within 24 hours.</p><p><strong>Severity:</strong> Informational</p><p><strong>Categories:</strong> Policy and Compliance, Regulatory</p><p><a href="https://cyber.netsecops.io/articles/eu-cyber-resilience-act-mandatory-reporting-deadline-approaches/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/eu-cyber-resilience-act-mandatory-reporting-deadline-approaches.jpg" type="image/jpeg" length="0"/>
      <category>Policy and Compliance</category>
      <category>Regulatory</category>
    </item>

    <item>
      <title>[UPDATED] Suspected Iranian Actors Target U.S. Water Utilities via Exposed PLCs</title>
      <link>https://cyber.netsecops.io/articles/coordinated-cyberattacks-hit-us-water-utilities-suspected-iranian-link/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/coordinated-cyberattacks-hit-us-water-utilities-suspected-iranian-link/</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>A coordinated series of cyberattacks has targeted water and wastewater facilities across at least seven U.S. states, with suspected links to Iranian state-sponsored actors. The attackers exploited internet-exposed Programmable Logic Controllers (PLCs), primarily from Rockwell Automation, to disrupt ...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Industrial Control Systems, Cyberattack, Threat Actor</p><p><a href="https://cyber.netsecops.io/articles/coordinated-cyberattacks-hit-us-water-utilities-suspected-iranian-link/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/coordinated-cyberattacks-hit-us-water-utilities-suspected-iranian-link.jpg" type="image/jpeg" length="0"/>
      <category>Industrial Control Systems</category>
      <category>Cyberattack</category>
      <category>Threat Actor</category>
    </item>

    <item>
      <title>[UPDATED] Google Chrome 152 Patches 327 Flaws, Including 10 Critical Bugs</title>
      <link>https://cyber.netsecops.io/articles/google-chrome-152-patches-327-vulnerabilities-10-critical/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/google-chrome-152-patches-327-vulnerabilities-10-critical/</guid>
      <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>Google has released Chrome 152 for Windows, macOS, and Linux, a major security update that addresses 327 vulnerabilities. The patch includes fixes for 10 critical flaws, the majority of which are use-after-free memory corruption issues in components like ANGLE, Aura, and Chromecast that could lead t...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Patch Management, Vulnerability</p><p><a href="https://cyber.netsecops.io/articles/google-chrome-152-patches-327-vulnerabilities-10-critical/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/google-chrome-152-patches-327-vulnerabilities-10-critical.jpg" type="image/jpeg" length="0"/>
      <category>Patch Management</category>
      <category>Vulnerability</category>
    </item>

    <item>
      <title>[UPDATED] Critical JFrog Artifactory Auth Bypass Flaw Under Active Exploit</title>
      <link>https://cyber.netsecops.io/articles/critical-jfrog-artifactory-flaw-under-active-exploitation/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/critical-jfrog-artifactory-flaw-under-active-exploitation/</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>A critical authentication bypass vulnerability, CVE-2026-82329, in self-hosted JFrog Artifactory instances is being actively exploited. The flaw allows unauthenticated attackers to gain administrative privileges. Patches were released on August 28, 2026, and organizations are urged to update immedia...</p><p><strong>Severity:</strong> Critical</p><p><strong>Categories:</strong> Vulnerability, Supply Chain Attack, Patch Management</p><p><a href="https://cyber.netsecops.io/articles/critical-jfrog-artifactory-flaw-under-active-exploitation/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/critical-jfrog-artifactory-flaw-under-active-exploitation.jpg" type="image/jpeg" length="0"/>
      <category>Vulnerability</category>
      <category>Supply Chain Attack</category>
      <category>Patch Management</category>
    </item>

    <item>
      <title>[UPDATED] AI Research Firm METR Discloses $600k API Key Theft</title>
      <link>https://cyber.netsecops.io/articles/ai-research-firm-metr-discloses-api-key-theft-and-cyberattacks/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/ai-research-firm-metr-discloses-api-key-theft-and-cyberattacks/</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>AI safety non-profit METR disclosed two security incidents. In March 2026, a stolen API key was used to fraudulently consume approximately $600,000 in AI credits. In May, a separate, sustained campaign involved automated probing of its public infrastructure, credential stuffing, and phishing.</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Cyberattack, Cloud Security, Data Breach</p><p><a href="https://cyber.netsecops.io/articles/ai-research-firm-metr-discloses-api-key-theft-and-cyberattacks/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/ai-research-firm-metr-discloses-api-key-theft-and-cyberattacks.jpg" type="image/jpeg" length="0"/>
      <category>Cyberattack</category>
      <category>Cloud Security</category>
      <category>Data Breach</category>
    </item>

    <item>
      <title>[UPDATED] Attackers Hijack AI API Keys to Fuel Gray Market "Transfer Stations"</title>
      <link>https://cyber.netsecops.io/articles/token-jacking-cybercriminals-stealing-ai-resources/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/token-jacking-cybercriminals-stealing-ai-resources/</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>A new threat dubbed "token jacking" has emerged where attackers steal AI API keys from developers to power illicit "transfer stations." These gray market services resell access to premium AI models at a fraction of the cost, often fueled by stolen credentials. Attackers are using methods like inform...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Cloud Security, Threat Intelligence, Supply Chain Attack</p><p><a href="https://cyber.netsecops.io/articles/token-jacking-cybercriminals-stealing-ai-resources/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/token-jacking-cybercriminals-stealing-ai-resources.jpg" type="image/jpeg" length="0"/>
      <category>Cloud Security</category>
      <category>Threat Intelligence</category>
      <category>Supply Chain Attack</category>
    </item>

    <item>
      <title>[UPDATED] Threat Actors Use AI Scripts to Target Siemens PLCs in Critical Infrastructure</title>
      <link>https://cyber.netsecops.io/articles/threat-actors-use-ai-scripts-to-target-siemens-plcs-in-us-critical-infrastructure/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/threat-actors-use-ai-scripts-to-target-siemens-plcs-in-us-critical-infrastructure/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>A joint advisory from U.S. agencies like the NSA and CISA warns of an ongoing campaign where threat actors are using AI-generated scripts to target Siemens S7 Series Programmable Logic Controllers (PLCs) in U.S. critical infrastructure. The attackers are using scanning tools to find exposed PLCs and...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Industrial Control Systems, Cyberattack, Threat Intelligence</p><p><a href="https://cyber.netsecops.io/articles/threat-actors-use-ai-scripts-to-target-siemens-plcs-in-us-critical-infrastructure/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/threat-actors-use-ai-scripts-to-target-siemens-plcs-in-us-critical-infrastructure.jpg" type="image/jpeg" length="0"/>
      <category>Industrial Control Systems</category>
      <category>Cyberattack</category>
      <category>Threat Intelligence</category>
    </item>

    <item>
      <title>[UPDATED] McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft</title>
      <link>https://cyber.netsecops.io/articles/mckesson-discloses-breach-shinyhunters-claims-patient-data-theft/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/mckesson-discloses-breach-shinyhunters-claims-patient-data-theft/</guid>
      <pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>U.S. healthcare giant McKesson has confirmed a cybersecurity incident involving unauthorized network access and data exfiltration. The ShinyHunters extortion group has claimed responsibility, alleging the theft of approximately one terabyte of data, including 284 million patient-related records, fro...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Data Breach, Threat Actor, Cloud Security</p><p><a href="https://cyber.netsecops.io/articles/mckesson-discloses-breach-shinyhunters-claims-patient-data-theft/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/mckesson-discloses-breach-shinyhunters-claims-patient-data-theft.jpg" type="image/jpeg" length="0"/>
      <category>Data Breach</category>
      <category>Threat Actor</category>
      <category>Cloud Security</category>
    </item>

    <item>
      <title>[UPDATED] Boston Scientific Operations Crippled by Major Global Cyberattack</title>
      <link>https://cyber.netsecops.io/articles/boston-scientific-operations-crippled-by-major-cyberattack/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/boston-scientific-operations-crippled-by-major-cyberattack/</guid>
      <pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>Medical technology giant Boston Scientific is grappling with a significant cyberattack that triggered a global network outage, severely disrupting its manufacturing, order processing, and shipping capabilities. The incident, first identified on August 25, 2026, has led to a multi-day operational sta...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Cyberattack, Industrial Control Systems, Threat Intelligence</p><p><a href="https://cyber.netsecops.io/articles/boston-scientific-operations-crippled-by-major-cyberattack/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/boston-scientific-operations-crippled-by-major-cyberattack.jpg" type="image/jpeg" length="0"/>
      <category>Cyberattack</category>
      <category>Industrial Control Systems</category>
      <category>Threat Intelligence</category>
    </item>

    <item>
      <title>[UPDATED] ATF Confirms Major Incident After Qilin Ransomware Breach Claim</title>
      <link>https://cyber.netsecops.io/articles/atf-confirms-major-incident-after-qilin-ransomware-breach-claim/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/atf-confirms-major-incident-after-qilin-ransomware-breach-claim/</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a 'major' cybersecurity incident following a claim by the Qilin ransomware gang. On August 26, 2026, Qilin listed the federal agency on its dark web leak site. The ATF stated the breach was contained to a 'standalone co...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Ransomware, Data Breach, Threat Actor</p><p><a href="https://cyber.netsecops.io/articles/atf-confirms-major-incident-after-qilin-ransomware-breach-claim/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/atf-confirms-major-incident-after-qilin-ransomware-breach-claim.jpg" type="image/jpeg" length="0"/>
      <category>Ransomware</category>
      <category>Data Breach</category>
      <category>Threat Actor</category>
    </item>

    <item>
      <title>[UPDATED] Manchester Airports Group Breach Exposes 8.7 Million Customers' Data</title>
      <link>https://cyber.netsecops.io/articles/manchester-airports-group-breach-exposes-data-of-8-7-million-customers/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/manchester-airports-group-breach-exposes-data-of-8-7-million-customers/</guid>
      <pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>Manchester Airports Group (MAG), operator of Manchester, Stansted, and East Midlands airports in the UK, has suffered a data breach affecting approximately 8.7 million customers. An unauthorized third party accessed a system containing customer information related to bookings for services like car p...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Data Breach, Cyberattack</p><p><a href="https://cyber.netsecops.io/articles/manchester-airports-group-breach-exposes-data-of-8-7-million-customers/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/manchester-airports-group-breach-exposes-data-of-8-7-million-customers.jpg" type="image/jpeg" length="0"/>
      <category>Data Breach</category>
      <category>Cyberattack</category>
    </item>

    <item>
      <title>[UPDATED] Unpatched "ShieldBreak" Zero-Day Hits Microsoft Defender (CVE-2026-69414)</title>
      <link>https://cyber.netsecops.io/articles/shieldbreak-unpatched-zero-day-microsoft-defender-lpe-cve-2026-69414/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/shieldbreak-unpatched-zero-day-microsoft-defender-lpe-cve-2026-69414/</guid>
      <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>A new unpatched zero-day vulnerability named "ShieldBreak" (CVE-2026-69414) affects the Microsoft Malware Protection Engine in Microsoft Defender. The flaw allows a local, low-privilege attacker to escalate their privileges to SYSTEM. A proof-of-concept exploit is publicly available, and Microsoft h...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Vulnerability, Patch Management, Malware</p><p><a href="https://cyber.netsecops.io/articles/shieldbreak-unpatched-zero-day-microsoft-defender-lpe-cve-2026-69414/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/shieldbreak-unpatched-zero-day-microsoft-defender-lpe-cve-2026-69414.jpg" type="image/jpeg" length="0"/>
      <category>Vulnerability</category>
      <category>Patch Management</category>
      <category>Malware</category>
    </item>

    <item>
      <title>[UPDATED] Boston Scientific Suffers Global Disruption from Major Cyberattack</title>
      <link>https://cyber.netsecops.io/articles/boston-scientific-cyberattack-disrupts-global-operations/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/boston-scientific-cyberattack-disrupts-global-operations/</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>Medical device manufacturer Boston Scientific has been hit by a significant cyberattack, resulting in a global network outage and severe disruption to its business operations. The incident, detected on August 25, 2026, has impacted the company's ability to process and ship customer orders worldwide....</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Cyberattack, Data Breach, Threat Intelligence</p><p><a href="https://cyber.netsecops.io/articles/boston-scientific-cyberattack-disrupts-global-operations/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/boston-scientific-cyberattack-disrupts-global-operations.jpg" type="image/jpeg" length="0"/>
      <category>Cyberattack</category>
      <category>Data Breach</category>
      <category>Threat Intelligence</category>
    </item>

    <item>
      <title>[UPDATED] US Seizes Chinese Hacking Platforms Targeting Critical Infrastructure</title>
      <link>https://cyber.netsecops.io/articles/us-seizes-chinese-hacking-platforms-qscan-qtrouter-targeting-critical-infrastructure/?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=updates</link>
      <guid isPermaLink="true">https://cyber.netsecops.io/articles/us-seizes-chinese-hacking-platforms-qscan-qtrouter-targeting-critical-infrastructure/</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[<p>The U.S. Department of Justice and FBI have seized domains used by a Chinese state-sponsored hacking group known as 'QTFY' to operate two malicious platforms: 'QScan' and 'QTRouter'. These tools were part of a multi-year campaign targeting U.S. critical infrastructure, including NASA, the Federal Re...</p><p><strong>Severity:</strong> High</p><p><strong>Categories:</strong> Threat Actor, Cyberattack, Policy and Compliance</p><p><a href="https://cyber.netsecops.io/articles/us-seizes-chinese-hacking-platforms-qscan-qtrouter-targeting-critical-infrastructure/">Read Full Article →</a></p>]]></description>
      <enclosure url="https://cyber.netsecops.io/images/og-image/us-seizes-chinese-hacking-platforms-qscan-qtrouter-targeting-critical-infrastructure.jpg" type="image/jpeg" length="0"/>
      <category>Threat Actor</category>
      <category>Cyberattack</category>
      <category>Policy and Compliance</category>
    </item>
  </channel>
</rss>