CyberNews: 30/08/2026 Edition

Published by Dunateo on 2026-08-30

Today’s roundup

  • Ivanti Patches Third Zero-Day in Connect Secure VPNs
  • LockBit Ransomware Group Says It's Still Operational Days After Law Enforcement Disruption
  • Microsoft February 2024 Patch Tuesday fixes 73 flaws, including 3 zero-days
  • Critical Vulnerability Discovered in Apache ActiveMQ, Actively Exploited
  • Researchers Uncover New Malware Campaign Targeting Industrial Control Systems
  • Google Patches Chrome Zero-Day Vulnerability (CVE-2024-xxxx)
  • Zero-Day in PHP-FPM 'File Descriptor Leak' Leads to Local Privilege Escalation
  • Vulnerability in popular WordPress plugin puts 1 million sites at risk
  • Over 1.4 Million Gen Z Workers Targeted by Phishing Scam
  • Summary

    Ivanti has patched a third actively exploited zero-day, CVE-2024-21894, affecting Connect Secure and Policy Secure VPNs, which allows for privilege escalation. Organizations are urged to apply updates immediately to mitigate the threat.

    Days after an international law enforcement disruption, the LockBit ransomware group claims it has recovered, moved its servers, and is resuming operations, threatening to leak data from previously compromised victims.

    Microsoft's February 2024 Patch Tuesday addressed 73 vulnerabilities, including three actively exploited zero-days: CVE-2024-21351 (SmartScreen bypass), CVE-2024-21410 (Exchange Server EoP), and CVE-2024-21412 (Common Log File System RCE).

    A critical remote code execution vulnerability (CVE-2023-46604) in Apache ActiveMQ has been actively exploited since October 2023, with threat actors deploying ransomware. Patches are available and should be applied promptly.

    Researchers have uncovered "Pipedream 2.0," a new and sophisticated malware campaign targeting Industrial Control Systems (ICS). Attributed to state-sponsored actors, it features enhanced modules for reconnaissance and manipulation of critical infrastructure.

    Google has released an emergency update for its Chrome browser to address a newly discovered and actively exploited zero-day vulnerability (CVE-2024-xxxx), urging users to update immediately.

    A new zero-day vulnerability affecting PHP-FPM, related to a file descriptor leak, has been discovered. This flaw allows for local privilege escalation on web servers running PHP.

    A critical vulnerability affecting a popular WordPress plugin, installed on over 1 million sites, has been disclosed. The flaw could allow remote code execution or data exfiltration, and patches are available.

    A large-scale phishing campaign is actively targeting over 1.4 million Gen Z workers. The scam uses fake job offers, primarily distributed via LinkedIn and other platforms, to deliver information-stealing malware.

    Want to dig deeper?

    Vulnerabilities

    CVE-2024-21894 High
    CVE-2024-21351 Medium
    CVE-2024-21410 High
    CVE-2024-21412 High
    CVE-2023-46604 Critical