CISA: WatchGuard RCE flaw now exploited in ransomware attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. This flaw is tracked as CVE-2025-14733 and stems from an out-of-bounds write allowing unauthenticated threat actors to execute malicious code remotely in low-complexity attacks. This vulnerability affects firewalls running […]
Microsoft fixes bug that wiped Windows desktop settings
Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. The company confirmed last week, after a wave of user reports that their wallpaper switched to a black background automatically, that this bug is triggered after installing the KB5120998 August 2026 preview update on Windows 11 24H2 and Windows 11 25H2 […]
Trezor warns users of email provider breach, phishing attacks
Cryptocurrency hardware wallet maker Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. Affected customers received fake “critical security alert” emails from help@trezor.io claiming that a “hardware microcontroller vulnerability” in the STM32 microcontrollers used by Trezor cold storage wallets could expose their seeds to […]
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. “In August […]
AdaptHealth confirms 4.1 million people exposed in July cyberattack
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. The company provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products. AdaptHealth first disclosed the incident in a filing with […]
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. Devices running firmware version 1.0.0.28 are affected by a high-severity vulnerability tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3 (model S2DCW) […]
US says Chinese firms extracted billions of tokens from frontier AI models
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. A joint advisory from CISA, NSA, and the FBI states that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens through millions of requests from frontier AI […]
Veradigm warns of patient data breach after ransomware gang claims attack
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients’ personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical […]
Over 36,000 exposed Plex servers vulnerable to recent flaws
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking. While the company didn’t provide additional details on Tuesday when it issued the warning, these security […]
Man gets 15 years for extorting women with AI-generated porn videos
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims via phone calls, voicemails, text messages, and online posts. When he was arrested on federal charges on June 23, 2025, 37-year-old James Strahler II was also charged with anonymous telecommunications harassment and child pornography production and distribution. […]