Breaking News – Cyber Threats (last 6h)
Generated: 2026-03-20 13:00 PDT
- Oracle pushes emergency fix for critical Identity Manager RCE flaw
BleepingComputer • 2026-03-20 11:48 • www.bleepingcomputer.com
Oracle has released an out-of-band security update to fix a critical unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager tracked as CVE-2026-21992. […]
https://www.bleepingcomputer.com/news/security/oracle-pushes-emergency-fix-for-critical-identity-manager-rce-flaw/ - Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets
The Hacker News • 2026-03-20 10:47 • thehackernews.com
Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to deliver malware that stole sensitive CI/CD secrets.
The latest incident impacted GitHub Actions “aquasecurity/trivy-action” and “aquasecurity/setup-trivy,” which are used to scan Docker container images for vulnerabilities and set up GitHub Actions workflow
https://thehackernews.com/2026/03/trivy-security-scanner-github-actions.html - Police take down 373,000 fake CSAM sites in Operation Alice
BleepingComputer • 2026-03-20 10:19 • www.bleepingcomputer.com
An international law enforcement action called Operation Alice has shut down over 373,000 dark web sites that offered fake CSAM packages. […]
https://www.bleepingcomputer.com/news/security/police-take-down-373-000-fake-csam-sites-in-operation-alice/ - Denver’s crosswalks hacked to broadcast anti-Trump messages
Graham Cluley • 2026-03-20 08:24 • www.bitdefender.com
Pedestrians crossing a street in Denver, Colorado, got rather more than they bargained for last weekend, when the audio signals at two crosswalks began broadcasting a political message alongside their usual walking instructions.Read more in my article on the Hot for Security blog.
https://www.bitdefender.com/en-us/blog/hotforsecurity/denvers-crosswalks-hacked-broadcast-anti-trump-messages - Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
The Hacker News • 2026-03-20 08:15 • thehackernews.com
A critical security flaw impacting Langflow has come under active exploitation within 20 hours of public disclosure, highlighting the speed at which threat actors weaponize newly published vulnerabilities.
The security defect, tracked as CVE-2026-33017 (CVSS score: 9.3), is a case of missing authentication combined with code injection that could result in remote code execution.
“The POST /api/v1
https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.html - CISA orders feds to patch max-severity Cisco flaw by Sunday
BleepingComputer • 2026-03-20 08:09 • www.bleepingcomputer.com
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity vulnerability, CVE-2026-20131, in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22. […]
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-cisco-flaw-by-sunday/ - How CISOs Can Survive the Era of Geopolitical Cyberattacks
BleepingComputer • 2026-03-20 07:01 • www.bleepingcomputer.com
Geopolitical tensions are driving destructive cyberattacks designed to disrupt operations, not demand ransom. CISOs must limit lateral movement and contain breaches to reduce the impact of wiper campaigns. […]
https://www.bleepingcomputer.com/news/security/how-cisos-can-survive-the-era-of-geopolitical-cyberattacks/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
