I explain cybersecurity news, active attacks, privacy, surveillance technology, vulnerabilities, and OSINT in plain English, then give my independent analysis.
Representative preview—not live observations. Open the Live Threat Center for sourced data and map limitations.
LIVE THREAT FEED
Actively exploited vulnerabilities
Current entries from CISA’s official Known Exploited Vulnerabilities catalog. These are confirmed weaknesses attackers have used, not simulated attack-map traffic.
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
ACTIVE EXPLOITATION
CVE-2026-102489: Zammad GmbH Zammad
Zammad GmbH Zammad Session Fixation Vulnerability
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
ACTIVE EXPLOITATION
CVE-2026-104286: Fortinet FortiMail
Fortinet FortiMail Path Traversal Vulnerability
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
ACTIVE EXPLOITATION
CVE-2026-86950: Apple Multiple Products
Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
ACTIVE EXPLOITATION
CVE-2026-88772: Citrix NetScaler
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
South Korea orders bank security checks after multiple customer-data breaches
South Korea's Financial Services Commission convened an emergency meeting and ordered financial institutions to inspect internet-exposed systems after several banks reported unauthorized access. Shinhan Bank says roughly 25,000 customers were affected, while KB Kookmin and Hana Bank disclosed smaller exposures.