A maximum-severity vulnerability (CVSS 10.0) in Cisco SD-WAN is being actively attacked – marking the second critical flaw in Cisco’s network control system exploited this year.
The U.S. House Committee on Homeland Security is pressing Instructure over the Canvas cyberattack, with the inquiry coming on the same day the company announced a settlement with the ShinyHunters cybercriminals.
Cisco patches critical authentication vulnerability (CVE-2026-20182, CVSS 10.0) in SD-WAN Controller that is already being actively exploited; unpatched systems allow unauthenticated attackers admin access and control of the entire SD-WAN infrastructure.
Cisco patches critical authentication vulnerability (CVE-2026-20182) in Catalyst SD-WAN Controller with maximum CVSS score of 10.0; the vulnerability is already being actively exploited in targeted attacks and enables unauthenticated access for admin escalation.
Three versions of the npm package node-ipc (9.1.23, 9.2.3, 10.1.1) contain malware that steals developer and cloud access credentials upon package loading and transmits them to a C2 server, targeting over 90 categories of login credentials.
Three versions of the popular Node-IPC npm package were infected with stealer malware that exfiltrates up to 90 categories of developer and cloud secrets, published by an unauthorized account and sending data to external C2 servers.
The Belarusian threat actor ‘FrostyNeighbor’ conducts targeted spear-phishing campaigns against Polish and Ukrainian government agencies based on individualized reconnaissance and espionage operations.
In Q1 2026, startup financing surpasses M&A activity by over $1 billion for the first time – a rare phenomenon that widens the “valley of death” in cybersecurity and creates new risks for young companies.
Manufacturing companies face massively increased cyberattacks in 2026 as ransomware groups exploit the industry’s dependence on uninterrupted operations.
Anthropic introduces metering for Claude API usage, while developers switch to Codex, which offers more generous limits without explicit usage restrictions.
Securing traditional cloud workloads is already challenging; edge workloads face additional security obstacles, including a broader attack surface and greater exposure to physical attacks.
Securing traditional cloud workloads is already a challenge, and edge workloads face additional security obstacles, including a broader attack surface and greater exposure to physical attacks.