Apple released security updates to fix CVE-2026-20700, a memory corruption flaw in the dyld component that can allow arbitrary code execution. The company says the bug was used in an “extremely sophisticated” campaign against targeted individuals, underscoring the need to update iPhones, iPads, and Macs immediately.
Source: SecurityWeek
Critical BeyondTrust RCE under active attack within 24 hours of PoC
Threat actors began targeting CVE-2026-1731—an unauthenticated remote code execution flaw in BeyondTrust Remote Support—less than a day after a public proof-of-concept appeared. Organizations with internet-exposed instances should patch urgently, restrict access, and monitor for exploitation attempts.
Source: SecurityWeek
CISA adds exploited SolarWinds, Notepad++, and Microsoft flaws to KEV list
CISA warned that several vulnerabilities are being exploited in the wild, including a SolarWinds bug likely abused as a zero-day since December 2025, along with issues in Notepad++ and Microsoft products. Federal agencies and enterprises should prioritize remediation per the Known Exploited Vulnerabilities catalog and apply vendor mitigations without delay.
Source: SecurityWeek
Google: Nation-state hackers misuse Gemini across the attack lifecycle
Google’s Threat Intelligence Group reports state-backed actors from China, Iran, North Korea, and Russia are leveraging Gemini for reconnaissance, phishing lures, scripting, and tooling support. The team also observed a rise in model extraction (“distillation”) attempts, highlighting growing interest in cloning proprietary AI capabilities—even as Google says it has not seen breakthrough attacker capabilities yet.
Source: Google Threat Intelligence
Dutch telecom Odido confirms massive breach affecting 6.2 million customers
Odido disclosed that attackers accessed extensive personal data, including names, contact details, bank account numbers, and ID information. The scale and sensitivity of the leak heighten risks of targeted phishing, fraud, and SIM-related social engineering.
Source: Security Affairs
First malicious Outlook add-in goes rogue, steals 4,000 credentials and payment data
The once-legitimate “AgreeTo” Outlook add-in was repurposed into a phishing kit after the developer abandoned the project, enabling credential theft and payment data capture. The case spotlights add-in supply chain risk and the need to audit and restrict third‑party mail extensions.
Source: Malwarebytes
Malicious Chrome extensions posing as AI assistants steal API keys and emails
More than 30 Chrome extensions—installed by at least 260,000 users—masqueraded as helpful AI chatbots while exfiltrating API keys, email content, and other sensitive data. Several were still available in the Chrome Web Store, reinforcing the importance of extension allowlisting and continuous browser telemetry monitoring.
Source: The Register
You May Also Be Interested In...