ShieldBreak Zero-Day PoC Bypass Targets Microsoft Defender Patches A publicly shared proof of concept called ShieldBreak claims a working bypass for a previously patched Microsoft Defender flaw, raising the stakes for Windows endpoint defenders.
Gunra Ransomware Targeting Critical Infrastructure: What Website and Hosting Operators Should Know US federal agencies warn that Gunra ransomware affiliates are exploiting Fortinet vulnerabilities to break into critical infrastructure networks, steal data, and encrypt systems.
Gunra Ransomware Targeting Fortinet and Schneider Electric Edge Devices A joint South Korean and U.S. advisory warns that Gunra ransomware operators are chaining Fortinet and Schneider Electric vulnerabilities to breach critical infrastructure networks worldwide.
Linux Stable Kernel Patch for CVE-2026-68480: What Website Owners Should Do A follow-up round of Linux stable kernel releases shipped a single bug fix for the speculative execution data leakage vulnerability tracked as CVE-2026-68480, and website operators should plan their upgrades now.
Metabase Zero-Day Vulnerability: What Hosting Customers Should Know A maximum-severity Metabase zero-day vulnerability is being exploited in the wild, letting unauthenticated attackers run arbitrary SQL queries and gain admin access on exposed instances.
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation CISA has confirmed active exploitation of a critical TeamCity deserialization vulnerability, CVE-2026-63077. Here is what website owners and DevOps teams running on-premise build servers need to do next.
CISA Adds Langflow, Tomcat, and N-central Flaws to the KEV Catalog: What Website Owners Should Do On August 5, 2026, CISA added three actively exploited flaws to its KEV catalog, including a critical Langflow RCE, an Apache Tomcat path handling bug, and an N-central remote code execution chain. Here is what hosting customers and developers should patch first.