Android security updates released this month patch a high-severity vulnerability exploited as a zero-day to install commercial spyware on compromised devices.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a remote code execution (RCE) affecting most Zoho ManageEngine products to its catalog of bugs known to be exploited in the wild.
Microsoft says Cuba ransomware threat actors are hacking their way into victims networks via Microsoft Exchange servers unpatched against a critical server-side request forgery (SSRF) vulnerability also exploited in Play ransomware attacks.