Latest security news
- Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
- AI and Automation Fall Short of Sysadmin Expectations
- CISA sets a new SBOM baseline
- Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
- Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks
- Cisco FMC static credentials exploited by attackers (CVE-2026-20316)
- Google Releases Patches for 370 Vulnerabilities in Chrome 151
- Coordinated cyberattack hits more than 30 Minnesota water utilities
- NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices
- Data breach cost 2026 averaged $4.99 million, AI attacks ran higher
- LogoKit Phishing Kit Screenshots Victim Sites in Real Time
- The Average Cost of a Data Breach Rises to $5 Million
- Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
- Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
- NCSC Publishes Guidance to Aid Incident Response and Recovery
- Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
- AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
- Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
- Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
- Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
- NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The warning comes from Proofpoint, who detected emails carrying the concealed exploit hitting inboxes. “The subject lines and lures are banal, likely so the targeted user opens and skims the message, but dismisses the message as junk without …
(C) Do-Know.com (http://do-know.com/). Do not copy without permission from info at do-know.com.