Latest security news
- Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)
- OT Coalition Urges CISA to Mandate Federal OT Security
- FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
- Attackers Hide AI Prompt Injections Inside Phishing Emails
- Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading
- Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains
- Half of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns
- Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One
- Danish CPR Breach Highlights Challenge of Supply Chain Risk
- ClickFix Attack Hides VBScript Payload in Browser Cache
- Nikkei Discloses Two Employee Cloud Account Compromises
- Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities
- Critical Medical Devices Unable to Support PQC Transition
- ASOS Customers Receive Bizarre “Hacked” Message Amid Suspected Snowflake Compromise
- Police Urge Passkey Use After Surge in Cybercrime Profits
- Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds
- ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes
- New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic
One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products, and a few hours after watchTowr researchers published a technical rundown of the flaw, attackers have been spotted attempting to exploit it. CVE-2026-21589 PoC in action (Source: watchTowr) “Exploitation attempts have now started to hit our honeypot network,” threat intelligence vendor Previdian warned late Tuesday, and shared a list of attacker IPs. About CVE-2026-21589 CVE-2026-21589 …
(C) Do-Know.com (http://do-know.com/). Do not copy without permission from info at do-know.com.