Security Highlights Of The Week [08/26-3]
- AresISEC Security Team
- August 28, 2026
PaperCut Zero-Day Is Being Actively ExploitedPaperCut confirmed active exploitation of a vulnerability affecting PaperCut NG and MF, with attacks observed against customer environments before a full fix was available. Organizations with internet-exposed Application Servers were urged to immediately restrict web interface access to trusted IP addresses while remediation efforts...
Security Highlights Of The Week [08/26-2]
- AresISEC Security Team
- August 24, 2026
Zimbra RCE Is Being Actively Exploited Against Internet-Facing ServersAttackers are actively exploiting CVE-2026-73570 in Zimbra Collaboration, an unauthenticated command injection vulnerability affecting deployments with the optional SNMP package and notifications enabled. Successful exploitation allows arbitrary operating system commands to run as the Zimbra user, creating a path to persistence,...
Security Highlights Of The Week [08/26-1]
- AresISEC Security Team
- August 12, 2026
GeoServer Zero-Day Exploited Hours After Public DisclosureAttackers began exploiting an unpatched GeoServer vulnerability only hours after technical details became public. The SQL injection issue can reportedly be escalated to remote code execution against vulnerable deployments using affected data stores.Source: SecurityWeek Cisco Secure Firewall Vulnerability Is Under Active ExploitationAttackers are...
Security Highlights Of The Week [07/26-3]
- AresISEC Security Team
- July 20, 2026
SonicWall SMA1000 Zero-Days Hit Remote Access InfrastructureSonicWall confirmed active exploitation of two SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410. The chain combines unauthenticated SSRF with code execution paths that can ultimately give attackers root-level control over exposed remote access appliances, making it one of the week’s most urgent edge-device stories.Source: Help...
Security Highlights Of The Week [07/26-2]
- AresISEC Security Team
- July 13, 2026
Januscape Opens a New VM Escape Path on Both Intel and AMDResearchers disclosed Januscape, a Linux KVM vulnerability that allows guest-to-host escape on both Intel and AMD systems. Because it affects the shadow MMU path in KVM and was reportedly used as a zero-day in Google’s kvmCTF program, it...
Security Highlights Of The Week [07/26-1]
- AresISEC Security Team
- July 6, 2026
Cisco Confirms Active Exploitation of Unified CM FlawCisco confirmed that attackers are now exploiting CVE-2026-20230 in Unified Communications Manager. The bug is an unauthenticated SSRF issue that can be triggered remotely with crafted HTTP requests, putting core enterprise telephony infrastructure at risk.Source: BleepingComputer FortiBleed Credential Theft Now Linked to...
Security Highlights Of The Week [06/26-4]]
- AresISEC Security Team
- June 30, 2026
Ubiquiti Critical Vulnerabilities Are Now Being Exploited in AttacksCISA warned that threat actors are actively targeting three critical UniFi OS flaws, all rated 10.0. The bugs allow unauthorized changes, file access, and deeper system manipulation on exposed devices, making this one of the most urgent edge infrastructure stories of...
Security Highlights Of The Week [06/26-3]
- AresISEC Security Team
- June 23, 2026
Megalodon Supply Chain Attack Compromised More Than 5,000 GitHub RepositoriesMegalodon was one of the most significant developer ecosystem incidents in this batch, with attackers pushing thousands of commits across more than 5,000 public GitHub repositories in only a few hours. The campaign targeted GitHub Actions workflows and aimed to...
Security Highlights Of The Week [06/26-2]
- AresISEC Security Team
- June 15, 2026
Cisco SD WAN Zero Day Is Being Exploited to Gain Root AccessCisco warned that attackers are actively exploiting CVE-2026-20245 in Catalyst SD WAN Manager. The flaw is currently unpatched and allows low privileged attackers to escalate to root, which makes it especially dangerous in environments where the platform manages...
Security Highlights Of The Week [06/26-1]
- AresISEC Security Team
- June 8, 2026
Megalodon Supply Chain Attack Compromised More Than 5,000 GitHub RepositoriesMegalodon was one of the most significant developer ecosystem incidents in this batch, with attackers pushing thousands of commits across more than 5,000 public GitHub repositories in only a few hours. The campaign targeted GitHub Actions workflows and aimed to...
Security Highlights Of The Week [05/26-4]
- AresISEC Security Team
- June 1, 2026
Megalodon Supply Chain Attack Compromised More Than 5,000 GitHub RepositoriesMegalodon was one of the most significant developer ecosystem incidents in this batch, with attackers pushing thousands of commits across more than 5,000 public GitHub repositories in only a few hours. The campaign targeted GitHub Actions workflows and aimed to...
Security Highlights Of The Week [05/26-3]
- AresISEC Security Team
- May 25, 2026
PAN-OS Zero Day Under Active Exploitation Grants Root Access on FirewallsPalo Alto Networks confirmed active exploitation of CVE-2026-0300 in the PAN-OS Captive Portal. The flaw allows unauthenticated remote code execution with root privileges on exposed firewalls, making it one of the most urgent perimeter risks in this cycle.Source: Palo...