A recently disclosed authentication bypass in Palo Alto Networks PAN-OS (CVE-2026-0257) has been under active exploitation, with attacks starting just days after disclosure. The flaw impacts GlobalProtect portal/gateway components and enables attackers to bypass VPN login, prompting urgent patching and tight access controls for internet-exposed devices.
Source: SecurityWeek
Websites Can Now Infer Your Activity via SSD Signals, Researchers Warn
New research details “FROST,” a technique that lets websites use simple JavaScript to measure telltale SSD activity and infer what a user is doing. The method raises serious fingerprinting and privacy concerns, potentially enabling cross-site tracking or behavioral surveillance without traditional permissions.
Source: Wired
Dutch Police Dismantle Botnet of 17 Million Infected Devices
Dutch authorities have taken down a massive botnet linked to at least 17 million compromised computers, phones, tablets, and IoT devices. More than 200 servers in the Netherlands supported the operation, which was used to conduct wide-ranging malicious activities; owners are urged to update, reset, and check devices for compromise.
Source: The Hacker News
Critical WP Maps Pro Exploit Used to Create Rogue Admin Accounts
Attackers are actively exploiting a critical flaw in the WP Maps Pro WordPress plugin to create unauthorized administrator accounts on vulnerable sites. With over 15,000 sales on Envato, affected sites should update immediately, audit user accounts and logs for suspicious additions, and disable the plugin if patching isn’t possible.
Source: The Hacker News
Popular npm Package “Codex UI” Caught Stealing OpenAI Refresh Tokens
A malicious npm package named Codex UI—with roughly 27,000 weekly downloads—was found exfiltrating OpenAI refresh tokens, enabling potential account takeover and downstream abuse. Developers should remove the package, rotate all exposed tokens and API keys, and review CI/CD pipelines and dependency locks for supply chain contamination.
Source: HackRead
OWASP Releases Agent Memory Guard to Thwart AI Agent Memory Attacks
OWASP introduced Agent Memory Guard, an open-source runtime defense designed to stop adversaries from weaponizing AI agents through their persistent memory. By monitoring and governing what enters long-lived stores (chat history, vector DBs, scratchpads), it aims to prevent instruction hijacking, data leakage, and tool-call manipulation that can persist across sessions.
Source: Help Net Security
Server Seizures in the Netherlands Disrupt Infrastructure Tied to Iran’s Cyber Ops
Dutch investigators seized roughly 800 servers from hosting provider WorkTitans B.V., uncovering infrastructure allegedly supporting some of Iran’s most active cyber-espionage campaigns. The takedown underscores how sanctioned and rebranded infrastructure can persist behind front companies, and it may trigger rapid APT fallback and migration to new hosting.
Source: Check Point Blog
You May Also Be Interested In...