Microsoft Teams Vulnerability Allows Malware Delivery Through ...
A critical vulnerability in Microsoft Teams allows attackers to deliver malware through specially crafted meeting invitations.
Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.
Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.
Updated September 11, 2026 — all 201 published advisories are browsable here. The newest one is on the appliance that is supposed to be doing the protecting: a Cisco firewall management flaw under active attack and added to CISA's known-exploited list, on the console that controls the firewalls guarding the whole network (CVE-2026-20079). Behind it, a Chrome zero-day exploited in the wild, where simply visiting a booby-trapped site is enough to get code running on the machine (CVE-2026-87491), and a FreeIPA flaw that hands full administrator rights to anyone who connects without a password, on the directory server that decides who gets into everything else (CVE-2026-76578). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.
A critical vulnerability in Microsoft Teams allows attackers to deliver malware through specially crafted meeting invitations.
Nation-state attackers are actively exploiting a critical zero-day in Palo Alto GlobalProtect VPN to breach defense contractors. If you run GlobalProtect, apply the emergency patch now or isolate affected systems from the network immediately.
Read moreA Chinese state-sponsored group turned Anthropic's Claude into the hacker itself, building a framework that allowed the AI to independently infiltrate networks, harvest credentials, and steal data. This was the first documented case of AI doing the hacking, not just assisting it.
Read moreThis week's cybersecurity developments demonstrate how quickly attackers are co-opting existing infrastructure. From Google's disruption of the IPIDEA residential proxy network to Microsoft's 114-flaw Patch Tuesday, the patterns show attackers prioritizing persistence over speed.
Read moreCVE-2026-20805 is an information disclosure vulnerability in the Windows Desktop Window Manager that allows attackers to defeat ASLR protections. Despite its medium CVSS score of 5.5, the flaw is actively being exploited as a critical enabler for exploit chains.
Read moreOur CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.
Subscribe to our newsletter and get the latest security insights delivered to your inbox.