MikroTik under active exploitation: 122,500 routers expose SSH port, emergency patches available
Independent researchers are reverse-engineering the bugs using AI.
[link] [comments]
Independent researchers are reverse-engineering the bugs using AI.

| | Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. [link] [comments] |
It’s the largest documented surveillance wave in Serbia to date.

More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024.
https://www.securityweek.com/91-vulnerabilities-patched-in-spring-application-framework/

| | Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. [link] [comments] |
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware.


| | LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. [link] [comments] |

| | The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. [link] [comments] |


| | Hackers stole personal information, medical records, and financial information from the organization’s server. [link] [comments] |

| | When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. [link] [comments] |

| | The major browser update resolves roughly 80 critical- and high-severity security defects. [link] [comments] |
