Kiteworks Lifts Precautionary Shutdown Advisory After Threat Investigation
Kiteworks has lifted a precautionary advisory that asked customers with self-managed deployments to take systems offline for a nine-hour window. The company issued the guidance after receiving what it described…
Dutch Police Confirm Arrest in ShinyHunters Investigation
Dutch authorities have confirmed the arrest of a 24-year-old man from Amsterdam in an investigation involving the ShinyHunters group. Police said the person was expected to appear before the Rotterdam…
Microsoft Details NeedyMantis Post-Compromise Malware Used in Targeted Intrusions
Microsoft has published an analysis of NeedyMantis, a modular post-compromise malware family used to maintain access in targeted intrusions. Microsoft observed it at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations,…
MCP Python SDK OAuth Flaw Can Expose Credentials to Malicious Servers
A security advisory for the official Model Context Protocol Python SDK warns that affected OAuth client implementations can send OAuth credentials to an attacker-controlled token endpoint when they connect to…
Apple Patches CoreGraphics Zero-Day Reportedly Used in Targeted Attacks
Apple has issued security updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that can lead to arbitrary code execution when a device processes a maliciously crafted file. Apple says it…
Citrix NetScaler Zero-Days Under Active Exploitation: What Defenders Need to Do
Citrix has disclosed two critical remote-code-execution vulnerabilities in NetScaler ADC and NetScaler Gateway that were exploited before public disclosure. The flaws, CVE-2026-88771 and CVE-2026-88772, each carry a CVSS v4 score…
SEBI Seeks Comments on Cybersecurity Framework for MII Subsidiaries
India’s Securities and Exchange Board of India is seeking comments on a cybersecurity framework for subsidiaries of market infrastructure institutions, Law.asia reported. A consultation is not a final rule, but…
Airtel Says Its AI Security System Blocked 1.42 Million Malicious Links
Airtel says its AI-powered cybersecurity technology blocked 1.42 million malicious links in spam messages in India, Deccan Herald reported. The figure is a vendor-reported metric, so it should be read…
California Critical Access Hospital Discloses Cybersecurity Incident
A California critical access hospital has announced a cybersecurity incident, according to The HIPAA Journal. Healthcare incidents deserve careful reading because public notices can precede a complete technical investigation; an…
Satellite Communications Growth Expands the Cybersecurity Attack Surface
Growth in satellite communications is expanding the cyberattack surface across IoT, utilities and critical infrastructure, Industrial Cyber reported. The issue is not that satellite connectivity is inherently unsafe; it is…
