DKDKCISSPSearch
CYBERSECURITY NEWS · INTELLIGENCE · RESPONSE

DKCISSP

What happened. Why it matters. What defenders should do next.

NEWS DESK

Latest Cybersecurity News

Global cyber events, incidents, research and security developments tracked by the DKCISSP newsroom.

NEWS DESK

All latest stories

Cloud & IdentityInfosecurity Magazine · 1d ago · 3 sources

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability

The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to However, it became a target itself last week after noticing suspicious activity on September 24.

VulnerabilitiesBleepingComputer · 1d ago · 1 source

Kiteworks patches max severity code injection vulnerability

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution.

VulnerabilitiesBleepingComputer · 2d ago · 1 source

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.

AI SecurityHelp Net Security · 3d ago · 3 sources

LastPass warns employees before they share sensitive data with AI tools - Help Net Security

LastPass has announced an expansion of its Business Max offering to include AI Monitoring & Protect and Web Monitoring & Protect, new visibility and governance capabilities that enable organizations to identify and secure the AI tools, SaaS applications, and websites its employees use, all from its existing browser-native extension.

Cloud & IdentityThe Hacker News · 3d ago · 1 source

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.

Cloud & IdentityBleepingComputer · 5d ago · 1 source

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

RansomwareBleepingComputer · 6d ago · 2 sources

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.

VulnerabilitiesBleepingComputer · 7d ago · 1 source

Kiteworks urges 6-hour server shutdown over potential zero-day attacks

Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack.

RansomwareBleepingComputer · 7d ago · 1 source

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.

Cyber AttacksSC Media · 7d ago · 1 source

Was the Australia health portal incident a misconfiguration error?

Questions arose Sept. 25 as to whether the much-reported hack on the Australian government health portal was actually the work of an OpenAI agent — or did the portal’s own code direct the agent to an unauthenticated endpoint, which means the agent did what it was told to do.

Threat ResearchRapid7 · 7d ago · 1 source

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?

This wrap-up comes from the beautiful country of Belgium, where the Metasploit team is team-building and team-eating while we cheer on our very own teammates giving talks - shout-out to @jburgess-r7 who gave a wonderful talk about some of his 0day research.