DKDKCISSPSearch
CYBERSECURITY NEWS · INTELLIGENCE · RESPONSE

DKCISSP

What happened. Why it matters. What defenders should do next.

NEWS DESK

Latest Cybersecurity News

Global cyber events, incidents, research and security developments tracked by the DKCISSP newsroom.

NEWS DESK

All latest stories

Cloud & IdentityInfosecurity Magazine · 23h ago · 2 sources

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability

The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to However, it became a target itself last week after noticing suspicious activity on September 24.

Cloud & IdentityInfosecurity Magazine · 23h ago · 3 sources

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability

The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to However, it became a target itself last week after noticing suspicious activity on September 24.

VulnerabilitiesBleepingComputer · 1d ago · 1 source

Kiteworks patches max severity code injection vulnerability

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution.

VulnerabilitiesBleepingComputer · 2d ago · 1 source

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.

AI SecurityHelp Net Security · 3d ago · 3 sources

LastPass warns employees before they share sensitive data with AI tools - Help Net Security

LastPass has announced an expansion of its Business Max offering to include AI Monitoring & Protect and Web Monitoring & Protect, new visibility and governance capabilities that enable organizations to identify and secure the AI tools, SaaS applications, and websites its employees use, all from its existing browser-native extension.

Cloud & IdentityThe Hacker News · 3d ago · 1 source

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.

Cloud & IdentityBleepingComputer · 5d ago · 1 source

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

RansomwareBleepingComputer · 6d ago · 2 sources

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.