Healthcare technology provider CareCloud confirmed a data breach affecting 3.75 million people, with sensitive information including medical records, Social Security numbers, and bank details potentially exposed. The incident underscores how attackers increasingly target business-critical platforms rather than individual endpoints. For security teams, it’s a reminder to prioritize rapid vendor risk assessment and tighten controls around data access, retention, and logging.
Source: MalwareBytes Blog
Zombie Card: expired Visa contactless cards can still be used for purchases
Researchers demonstrated “Zombie Card” attacks in which expiration dates on some Visa credit cards can be manipulated to complete real contactless transactions. The practical implication is that card expiration—normally a trust boundary for payment systems—may be bypassed under certain conditions. Consumers and merchants should ensure payment flows enforce robust validation checks, and security teams should treat payment manipulation techniques as an evolving fraud vector.
Source: MalwareBytes Blog
Microsoft patches critical Entra ID RCE (CVE-2026-69836) actively exploited in the wild
Microsoft addressed a critical remote code execution vulnerability in Entra ID, CVE-2026-69836, with a CVSS score of 10.0, and reports indicate it is being exploited in the wild. Because Entra ID is central to authentication and authorization across Microsoft 365, Azure, and connected applications, successful exploitation can have outsized impact. Organizations should treat this as an urgent patch-and-check event: confirm remediation, review identity logs, and hunt for signs of compromise across authentication flows.
Source: Help Net Security
Citrix NetScaler authentication bypass (CVE-2026-19490) urged for immediate remediation
Citrix has issued guidance following patches for multiple NetScaler ADC and NetScaler Gateway vulnerabilities, including a critical authentication bypass flaw tracked as CVE-2026-19490. Authentication bypass issues are especially dangerous because they can turn external reachability into full or partial access without valid credentials. Citrix customers should verify affected appliances and upgrade to the recommended builds immediately, then review for potential unauthorized access attempts.
Source: Help Net Security
GitLab CVE-2026-19478 under active exploitation within days
GitLab disclosed that CVE-2026-19478 is now being actively exploited, allowing unauthenticated attackers to modify or delete public projects under certain conditions. The speed from disclosure to exploitation indicates threat actors are actively targeting exposed GitLab instances and moving quickly to weaponize new weaknesses. Teams should identify whether they’re running vulnerable versions, apply emergency patches, and monitor for suspicious project changes or unauthorized modifications.
Source: Security Affairs
TrueConf server flaws added to CISA KEV as attackers deploy PhantomCore
CISA added TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, and reporting indicates the Head Mare hacktivist group has been leveraging the bugs to deploy PhantomCore malware. Because TrueConf is an on-premises video conferencing/UC platform, successful exploitation may blend into normal business workflows and communications. Organizations using TrueConf should urgently apply patches, validate exposure across all deployments, and examine endpoints and servers for signs of PhantomCore activity.
Source: Security Week
AI brand impersonation campaigns increasingly tied to confirmed malware activity
Attackers are impersonating popular AI brands (including Perplexity, Claude, ChatGPT, and Copilot) to deliver information stealers, backdoors, and malicious extensions, according to MDR-focused research. Out of cases initially tagged for AI involvement, a subset was confirmed as malicious AI-related activity—suggesting “AI-themed” lures are moving from hype to operationalized threat delivery. The practical takeaway: improve user-facing controls (email/web filtering, extension controls) and harden threat detection for brand impersonation and credential-harvesting patterns.
Source: Help Net Security
You May Also Be Interested In...
Thousands of active AWS access keys remain publicly exposed
Senator asks US watchdog to review federal use of hacking tools
Microsoft rolls out 22 fresh security patches