This Week in Security Critical Flaws, Active Exploits and Data at Risk

Here are some of the top Cybersecurity news articles for the past week:

🛠️ Atlassian Patches Critical File Access Vulnerability
Atlassian released emergency Security updates for a critical arbitrary file access vulnerability, CVE-2026-21589, affecting eight Data Center products including Jira, Confluence and Bitbucket. The flaw could allow an unauthenticated attacker to access sensitive files within affected applications.
 
🕵️ FBI Removes Contractor Following PeopleSoft Breach
The FBI removed a third-party contractor following a breach linked to ShinyHunters involving an unpatched Oracle PeopleSoft vulnerability. Attackers reportedly exploited CVE-2026-35273 against an FBI recruiting portal and obtained personal information belonging to employees and applicants.
 
🌐 CISA Adds Critical Cisco SD-WAN Flaw to KEV Catalog
CISA added CVE-2026-76504, a critical Cisco Catalyst SD-WAN Manager vulnerability, to its Known Exploited Vulnerabilities catalog following confirmed exploitation. The vulnerability can allow an unauthenticated remote attacker to gain administrative API access to affected infrastructure.
 
💻 Attackers Claim Access to ASOS Snowflake Environment
Cybercriminals abused ASOS notification infrastructure to send extortion messages to mobile app users and claimed access to the retailer’s Snowflake environment. The claimed Snowflake compromise and theft of customer data had not been confirmed by ASOS at the time of reporting.
 
🛡️ Apple Patches CoreGraphics Zero-Day
Apple issued emergency updates addressing CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics. Apple said the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals, and processing maliciously crafted content could lead to arbitrary code execution.
Pinpoint Protocol lock logo

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read in five minutes or less — straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Pinpoint Protocol lock logo

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read in five minutes or less — straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.