Skip to main content
COSMICBYTEZ
LABS
News
Security
HOWTOs
Tools
Study
Training
More
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
Search
⌘
K
Subscribe
Press
Enter
to search or
Esc
to close
News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe
Home
Archives
Archives
Browse all content by date
May 2026
(108 articles)
May 13
716,000 Impacted by OpenLoop Health Data Breach
May 13
73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation
May 13
China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm
May 13
Foxconn Confirms Cyberattack Claimed by Nitrogen Ransomware Gang
May 13
Government to Scrutinize Instructure Over Canvas Disruption, Data Breach
May 13
Microsoft May 2026 Patch Tuesday: 137 Flaws Fixed, Zero Zero-Days
May 13
Škoda Warns of Customer Data Breach After Online Shop Hack
May 13
Microsoft May 2026 Patch Tuesday Fixes 120 Flaws, No Zero-Days
May 13
Microsoft Patches 138 Vulnerabilities Including DNS and Netlogon RCE Flaws
May 13
New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
May 13
CVE-2026-2993: SQL Injection in AIWU AI Chatbot WordPress Plugin
May 13
CVE-2026-8043: Ivanti Xtraction File Control & HTML Injection
May 13
Build a Production Monitoring Stack with Prometheus and Grafana
May 12
Exaforce Raises $125 Million for Agentic SOC Platform
May 12
Fortinet Warns of Critical RCE Flaws in FortiSandbox and FortiAuthenticator
May 12
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65 TB Canvas Leak
May 12
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI and More
May 12
SAP Fixes Critical Vulnerabilities in Commerce Cloud and S/4HANA
May 12
UK Fines Water Supplier $1.3M for Exposing Data of 664K Customers
May 12
West Pharmaceutical Services Hit by Disruptive Ransomware Attack
May 12
West Pharmaceutical Warns of Ransomware Attack Impacting Business Operations
May 12
Worm Redux: Fresh Mini Shai-Hulud Infections Bite npm Supply Chain
May 12
CVE-2025-61311: Reflected XSS in docuForm Managed Print Services v11.11c
May 12
CVE-2026-28872: Apple iOS & iPadOS Remote Denial-of-Service via Resource Exhaustion
May 12
CVE-2026-34260 — SAP S/4HANA SQL Injection via ABAP Enterprise Search
May 12
CVE-2026-34263 — SAP Commerce Cloud Unauthenticated RCE
May 12
Dell ECS and ObjectScale: Hard-Coded Credentials Vulnerability (CVE-2026-40636)
May 11
Build Application Firewalls Aim to Stop the Next Supply Chain Attack
May 11
GM Agrees to $12.75M California Settlement Over Sale of Drivers' Data
May 11
Google Detects First AI-Generated Zero-Day Exploit in the Wild
May 11
Google: Hackers Used AI to Develop Zero-Day Exploit for Web Admin Tool
May 11
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
May 11
Skoda Data Breach Hits Online Shop Customers
May 11
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
May 11
UK Water Utility Fined £963,900 After Cl0p Lurked Undetected for Nearly Two Years
May 11
Why Changing Passwords Doesn't End an Active Directory Breach
May 11
CVE-2021-47923: OpenCart 3.0.3.8 Session Fixation Enables Account Takeover
May 11
CVE-2021-47936: OpenCATS 0.9.4 Unauthenticated RCE via PHP File Upload
May 11
CVE-2026-6433: WordPress Plugin SQLi Enables Unauthenticated PHP Code Execution
May 11
CrowdSec: Deploy a Community-Powered Intrusion Prevention System
May 10
American Duo Sentenced for Hosting Laptop Farms for North Korean IT Workers
May 10
Canvas Breach Disrupts Schools & Colleges Nationwide
May 10
Canvas Login Portals Hacked in Mass ShinyHunters Extortion Campaign
May 10
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
May 10
Exploit Frenzy Threatens Millions via Critical cPanel Vulnerability
May 10
GM to Pay Over $12 Million in California Privacy Settlement Involving Driver Data
May 10
Hackers Abuse Google Ads and Claude.ai Chats to Push Mac Malware
May 10
Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
May 10
Multiple Universities Forced to Reschedule Final Exams After Canvas Cyber Incident
May 10
Ollama Out-of-Bounds Read Flaw Allows Remote Process Memory Leak
May 10
One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk
May 10
PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
May 10
Police Shut Down Reboot of Crimenetwork Marketplace, Arrest Admin
May 10
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
May 10
ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories
May 10
CVE-2026-42569: phpVMS Critical Unauthenticated Legacy Import Access
May 9
cPanel & WHM Release Fixes for Three New Vulnerabilities — Patch Now
May 9
Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads
May 9
Fake OpenAI Repository on Hugging Face Pushes Infostealer Malware
May 9
GM to Pay Over $12 Million in Largest-Ever CCPA Fine Over Driver Data
May 9
Ivanti Warns of New EPMM Flaw Exploited in Zero-Day Attacks
May 9
JDownloader Site Hacked to Replace Installers with Python RAT Malware
May 9
New Linux 'Dirty Frag' Zero-Day Gives Root on All Major Distros
May 9
Trellix Source Code Breach Highlights Growing Supply Chain Threats
May 9
Zara Data Breach Exposed Personal Information of 197,000 People
May 9
CVE-2026-25199: Apache CloudStack Proxmox Extension Allows Unauthorized Cross-Tenant Instance Access
May 9
CVE-2026-37431: Beauty Parlour Management System SQL Injection (CVSS 9.8)
May 9
CVE-2026-41583: ZEBRA Zcash Node Consensus Rule Bypass (CVSS 9.1)
May 9
CVE-2026-41588: RELATE Courseware Timing Attack in Authentication (CVSS 9.0)
May 9
CVE-2026-42193: Plunk Email Platform SNS Webhook Forgery
May 9
CVE-2026-42296: Argo Workflows templateReferencing Strict Mode Bypass
May 9
CVE-2026-8153: Universal Robots PolyScope OS Command Injection — Unauthenticated RCE on Industrial Robots
May 8
CISA Gives Federal Agencies Four Days to Patch Actively Exploited Ivanti Zero-Day
May 8
Ivanti Customers Confront Yet Another Actively Exploited Zero-Day in EPMM
May 8
NVIDIA Confirms GeForce NOW Data Breach Affecting Armenian Users
May 8
Trellix Source Code Breach Claimed by RansomHouse Hackers
May 8
CVE-2026-33109: Azure Managed Instance for Apache Cassandra Remote Code Execution (CVSS 9.9)
May 8
CVE-2026-41500: electerm macOS Command Injection via Install Script
May 8
CVE-2026-41501: electerm Linux Command Injection via Install Script
May 8
CVE-2026-42208: LiteLLM AI Gateway Pre-Auth SQL Injection
May 3
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
May 3
New Bluekit Phishing Kit Features AI Assistant and Automated Domain Registration
May 3
CVE-2026-5324: WordPress Brizy Page Builder Unauthenticated Stored XSS
May 2
ConsentFix v3 Automates Azure OAuth Abuse With Mass Compromise Potential
May 2
Critical cPanel Flaw Mass-Exploited in 'Sorry' Ransomware Attacks
May 2
Edu-Tech Firm Instructure Discloses Cyber Incident, Probes Impact on Canvas LMS
May 2
In Other News: Scattered Spider Member Arrested, SOC Metrics, NSA Tool Flaw
May 2
Microsoft Tests Modern Windows Run Dialog With Dark Mode and Faster Performance
May 2
Trellix Confirms Source Code Breach With Unauthorized Repository Access
May 2
CVE-2026-42779: Critical Apache MINA Deserialization Class Bypass
May 2
CVE-2026-43824: Argo CD ServerSideDiff Exposes Cleartext Kubernetes Secrets
May 2
CVE-2026-4882: Unauthenticated File Upload in WordPress User Registration Advanced Fields
May 2
CVE-2026-7458: Authentication Bypass via OTP Flaw in WordPress User Verification Plugin
May 1
15-Year-Old Detained Over French Govt Agency Data Breach
May 1
1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, and Intercom
May 1
Cisco Releases Open Source Tool for AI Model Provenance
May 1
Cyber Incident Responders Sentenced to 4 Years for Carrying Out Ransomware Attacks
May 1
EnOcean SmartServer Flaws Expose Buildings to Remote Hacking
May 1
Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
May 1
Top Five Sales Challenges Costing MSPs Cybersecurity Revenue
May 1
US Ransomware Negotiators Get 4 Years in Prison Over BlackCat Attacks
May 1
CVE-2026-31431: Linux Kernel Privilege Escalation via Incorrect Resource Transfer
May 1
CVE-2026-35051: Traefik ForwardAuth Authentication Bypass via Proxy Trust Abuse (CVSS 10.0)
May 1
CVE-2026-35547: FreeBSD libnv Heap Buffer Overflow Allows Out-of-Bounds Write
May 1
CVE-2026-39858: Traefik Forwarded-Header Sanitization Bypass in ForwardAuth and Snippet Middleware (CVSS 10.0)
May 1
Apache MINA Incomplete Deserialization Patch Leaves 2.1.X and 2.2.X Branches Vulnerable
May 1
Critical Stack-Based Buffer Overflow in Totolink NR1800X Router
May 1
Critical Authentication Bypass in WordPress Temporary Login Plugin
April 2026
(383 articles)
Apr 30
AI Finds 38 Security Flaws in Electronic Health Record Platform
Apr 30
Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now Available
Apr 30
Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks
Apr 30
European Commission Accuses Meta of Breaching Child Safety Rules
Apr 30
FBI Links Cybercriminals to Sharp Surge in Cargo Theft Attacks
Apr 30
Former Incident Responders Sentenced to 4 Years for Ransomware Attacks on Clients
Apr 30
France Investigates 15-Year-Old Over Alleged Hack of National ID Agency
Apr 30
Google Fixes CVSS 10 Gemini CLI RCE and Cursor Flaws Enable Code Execution
Apr 30
Hackers Earning Millions from Hijacked Cargo, FBI Says
Apr 30
Moldova's Health Insurance Agency Reports Possible Data Leak After Cyberattack
Apr 30
PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials
Apr 30
Sandhills Medical Says Ransomware Breach Affects 170,000
Apr 30
TeamPCP Hits SAP npm Packages With 'Mini Shai-Hulud' Supply Chain Attack
Apr 30
CVE-2026-36841: TOTOLINK N200RE V5 Command Injection
Apr 30
CVE-2026-41940: WebPros cPanel & WHM and WP2 Missing Authentication Vulnerability
Apr 29
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
Apr 29
cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug
Apr 29
Critical GitHub Vulnerability Exposed Millions of Repositories
Apr 29
European Police Dismantles €50 Million Crypto Investment Fraud Ring
Apr 29
GitHub Fixes RCE Flaw That Gave Access to Millions of Private Repos
Apr 29
Hackers Exploit RCE Flaws in Qinglong Task Scheduler for Cryptomining
Apr 29
Learning from the Vercel Breach: Shadow AI and OAuth Sprawl
Apr 29
SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack
Apr 29
Swiss Police Arrest 10 Suspected Members of Nigeria-Linked Crime Group Black Axe
Apr 29
US & China Partner on Scam Center Takedown in Dubai
Apr 29
Vect 2.0 Ransomware Acts as Wiper Thanks to Design Error
Apr 29
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
Apr 29
CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Vulnerability
Apr 29
CVE-2026-35155: Dell iDRAC10 Race Condition Enables Privilege Escalation
Apr 29
Snap One WattBox 800/820 Diagnostic Auth Bypass (CVE-2026-41446)
Apr 29
Google Chrome GPU Use-After-Free Sandbox Escape (CVE-2026-7333)
Apr 29
Building a Production-Ready Reverse Proxy with Traefik v3 and Docker
Apr 28
Broken VECT 2.0 Ransomware Acts as a Data Wiper for Large Files
Apr 28
Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
Apr 28
Feuding Ransomware Groups Leak Each Other's Data
Apr 28
Hackers Are Exploiting a Critical LiteLLM Pre-Auth SQLi Flaw
Apr 28
Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak
Apr 28
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
Apr 28
Video Service Vimeo Confirms Anodot Breach Exposed User Data
Apr 28
CVE-2024-46636: NASA EOSDIS MODAPS v8.1 SQL Injection
Apr 28
CVE-2026-30352: Remote Code Execution in leonvanzyl Autocoder via /devserver/start Command Injection (CVSS 9.8)
Apr 28
CVE-2026-40453: Apache Camel Header Filter Case-Variant Bypass Enables Network RCE (CVSS 9.9)
Apr 28
CVE-2026-40860: Apache Camel JMS Unsafe ObjectMessage Deserialization Enables Network RCE (CVSS 9.8)
Apr 28
CVE-2026-41462: ProjeQtor Unauthenticated SQL Injection in Login Endpoint Affects Versions 7.0 Through 12.4.3 (CVSS 9.8)
Apr 28
CVE-2026-41635: Apache MINA Class Allowlist Bypass Enables Arbitrary Code Execution (CVSS 9.8)
Apr 28
CVE-2026-7136: Totolink A8000RU OS Command Injection via CGI Handler wanIdx Argument (CVSS 9.8)
Apr 28
CVE-2026-7154: Totolink A8000RU OS Command Injection via CGI Handler
Apr 28
CVE-2026-7224: SQL Injection in Pizzafy Ecommerce System 1.0
Apr 27
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
Apr 27
Deepfake Voice Attacks Are Outpacing Defenses: What Security Leaders Should Know
Apr 27
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS and Crypto Fraud
Apr 27
Firefox Vulnerability Allows Tor User Fingerprinting Across 'New Identity' Resets
Apr 27
FTC: Americans Lost Over $2.1 Billion to Social Media Scams in 2025
Apr 27
Home Security Giant ADT Data Breach Affects 5.5 Million People
Apr 27
Incomplete Windows Patch Opens Door to Zero-Click Attacks by APT28
Apr 27
Medtronic Confirms Breach After Hackers Claim 9 Million Records Theft
Apr 27
Money Launderer for Crypto Thieves Given 5-Year Prison Sentence
Apr 27
Money Launderer Linked to $230M Crypto Heist Gets 70 Months in Prison
Apr 27
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
Apr 27
Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Apr 27
CVE-2026-6785: Memory Safety Bugs in Firefox and Thunderbird Enable Arbitrary Code Execution
Apr 27
CVE-2026-6786: Memory Safety Bugs in Firefox and Thunderbird
Apr 27
CVE-2026-7037: Unauthenticated OS Command Injection in Totolink A8000RU
Apr 27
CVE-2026-7077: SQL Injection in itsourcecode Courier Management System
Apr 27
OpenVAS / Greenbone: Open-Source Vulnerability Scanning
Apr 26
American Utility Firm Itron Discloses Breach of Internal IT Network
Apr 26
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Apr 26
China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors
Apr 26
Hypersonic Supply Chain Attacks: One Solution That Didn't Need to Know the Payload
Apr 26
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
Apr 26
Microsoft Now Lets Admins Uninstall Copilot on Enterprise Devices
Apr 26
Microsoft Patch Tuesday, March 2026 Edition
Apr 26
New 'Pack2TheRoot' Flaw Gives Hackers Root Linux Access
Apr 26
Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks
Apr 26
Patch Tuesday, April 2026 Edition
Apr 26
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms + 25 New Stories
Apr 26
CVE-2026-7002: SQL Injection in KLiK SocialMediaWebsite Private Message Handler
Apr 26
Typecho 1.3.0 Pingback SSRF via X-Pingback Manipulation (CVE-2026-7025)
Apr 25
ADT Says Customer Data Stolen in Cyber Intrusion
Apr 25
China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks
Apr 25
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
Apr 25
DORA and Operational Resilience: Credential Management as a Financial Risk Control
Apr 25
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
Apr 25
Microsoft Rolls Out Revamped Windows Insider Program
Apr 25
Microsoft to Roll Out Entra Passkeys on Windows in Late April
Apr 25
New BlackFile Extortion Group Linked to Surge of Vishing Attacks
Apr 25
Researchers Uncover Pre-Stuxnet 'fast16' Malware Targeting Engineering Software
Apr 25
Threat Actor Uses Microsoft Teams to Deploy New 'Snow' Malware
Apr 25
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
Apr 25
CVE-2025-29635: D-Link DIR-823X Command Injection Vulnerability
Apr 25
CVE-2026-21515: Azure IoT Central Elevation of Privilege — CVSS 9.9 Critical
Apr 25
CVE-2026-41248: Clerk.js Middleware Auth Bypass Exposes Protected Routes (CVSS 9.1)
Apr 25
CVE-2026-41478: Saltcorn SQL Injection Allows Full Database Compromise (CVSS 9.9)
Apr 25
CVE-2026-6951: simple-git RCE via --config Option Bypass (CVSS 9.8)
Apr 24
ADT Confirms Data Breach After ShinyHunters Leak Threat
Apr 24
Firestarter Malware Survives Cisco Firewall Updates and Security Patches
Apr 24
Windows Update Gets New Controls to Reduce Forced Restarts
Apr 24
Pipecat AI Framework RCE via LivekitFrameSerializer (CVE-2025-62373)
Apr 24
Kofax Capture Unauthenticated RCE via Exposed .NET Remoting Channel (CVE-2026-23751)
Apr 24
CVE-2026-24303: Microsoft Partner Center Privilege Escalation via Improper Access Control
Apr 24
CVE-2026-26210: KTransformers Unsafe Deserialization RCE via Unauthenticated ZMQ RPC
Apr 24
CVE-2026-32210: Microsoft Dynamics 365 Online SSRF Enables Unauthenticated Network Spoofing
Apr 24
CVE-2026-39440: FunnelFormsPro WordPress Plugin Remote Code Inclusion (CVSS 9.9)
Apr 24
Hackage Haskell Repository Stored XSS Enables Credential Theft (CVE-2026-40470)
Apr 24
CVE-2026-41309: OSSN Resource Exhaustion via Crafted Pixel Bomb Image Upload
Apr 24
SocialEngine Unauthenticated SQL Injection via Activity Endpoint (CVE-2026-41460)
Apr 24
CVE-2026-6885: Borg SPM 2007 Arbitrary File Upload Enables Remote Code Execution
Apr 24
CVE-2026-6886: Borg SPM 2007 Authentication Bypass Allows Login as Any User
Apr 24
CVE-2026-6887: Borg SPM 2007 SQL Injection Exposes Full Database Access Without Authentication
Apr 24
CVE-2026-6942: radare2-mcp OS Command Injection via Shell Metacharacter Filter Bypass
Apr 23
Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks
Apr 23
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
Apr 23
Trigona Ransomware Deploys Custom CLI Exfiltration Tool in Active Attacks
Apr 23
Vercel Finds More Compromised Accounts in Context.ai-Linked Breach
Apr 23
CVE-2018-25270: ThinkPHP 5.0.23 Remote Code Execution via Routing Parameter
Apr 23
CVE-2018-25272: ELBA5 5.8.0 RCE via Default Database Credentials and xp_cmdshell
Apr 23
CVE-2026-33656: EspoCRM Formula Engine Attachment sourceId Overwrite (CVSS 9.1)
Apr 23
CVE-2026-3844 — Breeze Cache WordPress Plugin Unauthenticated File Upload
Apr 23
CVE-2026-39987: Marimo Pre-Auth Remote Code Execution — CISA KEV Added
Apr 23
CVE-2026-41167: Jellystat Authenticated SQL Injection in Multiple API Endpoints (CVSS 9.1)
Apr 23
CVE-2026-41228 — Froxlor Path Traversal via def_language Parameter
Apr 23
CVE-2026-41229 — Froxlor PHP Code Injection via MySQL Server Settings
Apr 22
Former Ransomware Negotiator Pleads Guilty to BlackCat Attacks Against U.S. Companies
Apr 22
France Titres Confirms Data Breach as Hacker Offers Stolen Citizen Data for Sale
Apr 22
Hypersonic Supply Chain Attacks: AI Defense Stops Zero-Days Without Payload Knowledge
Apr 22
Kyber Ransomware Gang Uses Post-Quantum Encryption to Target Windows and ESXi
Apr 22
Microsoft Teams to Get Efficiency Mode for Low-Resource PCs
Apr 22
New Mirai Campaign Exploits RCE Flaw in End-of-Life D-Link Routers
Apr 22
New npm Supply Chain Attack Self-Spreads to Steal Developer Auth Tokens
Apr 22
Over 1,300 Microsoft SharePoint Servers Vulnerable to Ongoing Spoofing Attacks
Apr 22
Spain Dismantles Major $4.7M Manga Piracy Platform, Arrests Four
Apr 22
CVE-2017-20230: Perl Storable Stack Overflow — CVSS 10.0
Apr 22
CVE-2025-15638: Net::Dropbear Bundles Vulnerable libtomcrypt — CVSS 10.0
Apr 22
CVE-2026-21997: Oracle Life Sciences Empirica Signal Privilege Escalation (CVSS 8.5)
Apr 22
CVE-2026-22753: Spring Security Filter Chain Bypass via PathPatternRequestMatcher Servlet Path Mismatch
Apr 22
CVE-2026-6748: Critical Uninitialized Memory Flaw in Firefox and Thunderbird Web Codecs
Apr 22
Self-Hosted Password Manager with Vaultwarden
Apr 21
Actively Exploited Apache ActiveMQ Flaw Impacts 6,400 Exposed Servers
Apr 21
Cloud Platform Vercel Says Company Breached Through Third-Party AI Tool
Apr 21
Crypto Infrastructure Company Blames $290 Million Theft on North Korean Hackers
Apr 21
Elon Musk Fails to Appear for Questioning by French Police Over Sexualized AI Images on X
Apr 21
Former DigitalMint Ransomware Negotiator Pleads Guilty to $75.3M Extortion Scheme
Apr 21
French Government Agency France Titres Confirms Data Breach as Hacker Sells Citizen Data
Apr 21
Italian Regulator Fines National Postal Service Orgs $15 Million for Data Privacy Violations
Apr 21
No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks
Apr 21
Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk
Apr 21
CVE-2025-2749: Kentico Xperience Path Traversal Vulnerability
Apr 21
CVE-2026-24467: OpenAEV Password Reset Account Takeover
Apr 21
CVE-2026-29646: OpenXiangShan NEMU RISC-V Hypervisor Privilege Escalation (CVSS 9.8)
Apr 21
CVE-2026-32604: Spinnaker Clouddriver Remote Code Execution (CVSS 9.9)
Apr 21
CVE-2026-32613: Spinnaker Echo Spring Expression Language Injection (CVSS 9.9)
Apr 21
CVE-2026-39918: Vvveb CMS Unauthenticated PHP Code Injection via Install Endpoint
Apr 21
CVE-2026-5965: NewSoftOA Critical OS Command Injection (CVSS 9.8)
Apr 20
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
Apr 20
KelpDAO Suffers $290 Million Heist Tied to Lazarus Hackers
Apr 20
Microsoft Releases Emergency Updates to Fix Windows Server Issues
Apr 20
Next.js Creator Vercel Hacked
Apr 20
Researchers Detect ZionSiphon Malware Targeting Israeli Water and Desalination OT Systems
Apr 20
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files
Apr 20
The Backup Myth That Is Putting Businesses at Risk
Apr 20
The Gentlemen Ransomware Now Uses SystemBC for Bot-Powered Attacks
Apr 20
Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials
Apr 20
Vercel Employee's AI Tool Access Led to Data Breach
Apr 20
Vercel's Security Breach Started with Malware Disguised as Roblox Cheats
Apr 20
Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Apr 20
Why the Axios Attack Proves AI Is Mandatory for Supply Chain Security
Apr 20
CVE-2026-20122: Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
Apr 20
CVE-2026-32956: Critical Heap Buffer Overflow in silex SD-330AC and AMC Manager
Apr 20
CVE-2026-6595: SQL Injection in ProjectsAndPrograms School Management System
Apr 20
Email Authentication: Deploying SPF, DKIM, and DMARC to Stop Spoofing
Apr 19
6-Year Ransomware Campaign Targets Turkish Homes and SMBs
Apr 19
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
Apr 19
Adobe Patches Actively Exploited Zero-Day That Lingered for Months
Apr 19
Analysis of 216M Security Findings Shows a 4x Increase in Critical Risk (2026 Report)
Apr 19
Apple Account Change Alerts Abused to Send Phishing Emails
Apr 19
Microsoft Drops Its Second-Largest Monthly Patch Batch on Record
Apr 19
Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities
Apr 19
Microsoft, Salesforce Patch AI Agent Data Leak Flaws
Apr 19
NIST to Stop Rating Non-Priority Flaws Due to Volume Increase
Apr 19
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE
Apr 19
Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
Apr 19
Vercel Confirms Breach as Hackers Claim to Be Selling Stolen Data
Apr 19
CVE-2026-6568: KodExplorer Path Traversal in Public Share Handler
Apr 19
KodExplorer fileGet Auth Bypass — Unauthenticated Remote File Access
Apr 19
CVE-2026-6577: DjangoBlog Missing Authentication in OwnTracks logtracks Endpoint
Apr 19
CVE-2026-6580: DjangoBlog Hard-Coded Cryptographic Key in Amap API Handler
Apr 18
$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims
Apr 18
Critical Flaw in protobuf.js Library Enables JavaScript Code Execution
Apr 18
In Other News: Satellite Cybersecurity Act, $90K Chrome Flaw, Teen Hacker Arrested
Apr 18
Microsoft Teams Right-Click Paste Broken by Edge Update Bug
Apr 18
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
Apr 18
NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9 and Proxmox VE 9.0 Support
Apr 18
New Jersey Men Sentenced to Combined 17 Years for Running North Korean Laptop Farms
Apr 18
Recent Apache ActiveMQ Vulnerability Exploited in the Wild — CISA Adds CVE-2026-34197 to KEV
Apr 18
CVE-2025-36568: Dell PowerProtect Data Domain BoostFS Credential Exposure
Apr 18
CVE-2026-37749: SQL Injection Auth Bypass in CodeAstro Attendance System (CVSS 9.8)
Apr 18
CVE-2026-40285: WeGIA SQL Injection via PHP extract() Session Override (CVSS 8.8)
Apr 18
CVE-2026-40492: SAIL XWD Codec Heap Buffer Overflow (CVSS 9.8)
Apr 18
CVE-2026-40493: SAIL PSD Codec Buffer Overflow via channels * depth Miscalculation (CVSS 9.8)
Apr 18
CVE-2026-40494: SAIL TGA Codec RLE Decoder Asymmetric Bounds Check (CVSS 9.8)
Apr 18
CVE-2026-6284: PLC Brute Force Password Bypass (CVSS 9.1)
Apr 18
CVE-2026-6518: WordPress CMP Plugin Arbitrary File Upload and Remote Code Execution (CVSS 8.8)
Apr 17
CISA Flags Apache ActiveMQ Flaw as Actively Exploited in Attacks
Apr 17
Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul
Apr 17
Grinex Exchange Blames Western Intelligence for $13.7M Crypto Hack, Suspends Operations
Apr 17
Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts
Apr 17
Payouts King Ransomware Uses QEMU Virtual Machines to Bypass Endpoint Security
Apr 17
Ransomware Attack Still Disrupting London Healthcare Nearly Two Years Later
Apr 17
Recently Leaked Windows Zero-Days Now Exploited in Active Attacks
Apr 17
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Apr 17
Ukraine Confirms APT28 Campaign Targeting Prosecutors and Anti-Corruption Agencies
Apr 17
CVE-2026-40259 — SiYuan Knowledge Management Authorization Bypass
Apr 17
CVE-2026-40322: SiYuan XSS via Mermaid innerHTML Injection
Apr 17
CVE-2026-6443: WordPress Accordion Plugin Backdoor in Version 1.4.6
Apr 12
CVE-2026-6112: Totolink A7100RU OS Command Injection via setRadvdCfg
Apr 12
CVE-2026-6113: Totolink A7100RU OS Command Injection via setTtyServiceCfg
Apr 12
CVE-2026-6114: Totolink A7100RU OS Command Injection via setNetworkCfg
Apr 12
CVE-2026-6115: Totolink A7100RU OS Command Injection via setAppCfg
Apr 11
Can Anthropic Keep Its Exploit-Writing AI Out of the Wrong Hands?
Apr 11
ChatGPT Rolls Out New $100 Pro Subscription to Challenge Claude
Apr 11
Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
Apr 11
Commerce Setting Up New AI Export Regime to Push Adoption of 'American AI' Abroad
Apr 11
In Other News: Cyberattack Stings Stryker, Windows Zero-Day, China Supercomputer Hack
Apr 11
Orthanc DICOM Vulnerabilities Lead to Crashes, RCE
Apr 11
Over 20,000 Crypto Fraud Victims Identified in International Crackdown
Apr 11
Your Next Breach Will Look Like Business as Usual
Apr 11
CVE-2026-31845: Rukovoditel CRM Reflected XSS in Zadarma API (CVSS 9.3)
Apr 11
CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution RCE (CVSS 9.6)
Apr 11
CVE-2026-4149: Sonos Era 300 Unauthenticated RCE via SMB Out-Of-Bounds Access
Apr 11
CVE-2026-5412: Juju Controller Facade Allows Low-Privilege Cloud Credential Theft
Apr 11
CVE-2026-6057: FalkorDB Browser Unauthenticated Path Traversal RCE
Apr 10
1 Billion CISA KEV Records Reveal Human-Scale Security Has Hit Its Limit
Apr 10
Dutch Hospitals Disrupted After Ransomware Hits Healthcare IT Provider ChipSoft
Apr 10
Healthcare IT Solutions Provider ChipSoft Hit by Ransomware Attack
Apr 10
Hims & Hers Breach Exposes the Most Sensitive Kinds of Patient PHI
Apr 10
'It Reads Like a Spy Novel': $280M Drift Theft Linked to North Korean Fake Companies
Apr 10
UK Government Threatens Tech Bosses With Jail Time Over AI Nudification Tools
Apr 10
CVE-2025-57735: Apache Airflow JWT Token Not Invalidated on Logout
Apr 10
CVE-2026-34177: Canonical LXD Incomplete VM Restriction Denylist
Apr 10
CVE-2026-34178: Canonical LXD Backup Import Path Restriction Bypass
Apr 10
CVE-2026-34578: OPNsense LDAP Injection Enables Auth Bypass
Apr 10
CVE-2026-5977: TOTOLINK A7100RU Critical OS Command Injection via setWiFiBasicCfg
Apr 10
CVE-2026-5978: TOTOLINK A7100RU Critical OS Command Injection via setWiFiAclRules
Apr 10
CVE-2026-6004: SQL Injection in code-projects Simple IT Discussion Forum
Apr 9
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
Apr 9
Breach Exposes Sensitive LAPD Files Stored in City Attorney System
Apr 9
Cryptocurrency ATM Giant Bitcoin Depot Reports $3.6 Million Stolen in Cyberattack
Apr 9
Cybercriminals Target Accountants to Drain Russian Firms' Bank Accounts
Apr 9
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
Apr 9
Eurail Says December Data Breach Impacts 300,000 Individuals
Apr 9
FCC Proposes New Rule to Further Crack Down on Illegal Robocalls
Apr 9
Hackers Exploiting Acrobat Reader Zero-Day Flaw Since December
Apr 9
Hackers Steal $3.6 Million from Crypto ATM Giant Bitcoin Depot
Apr 9
Healthcare IT Provider ChipSoft Hit by Ransomware, Services Taken Offline
Apr 9
Microsoft Suspends Dev Accounts for High-Profile Open Source Projects
Apr 9
Russia's Forest Blizzard Harvests Logins via SOHO Router DNS Poisoning
Apr 9
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
Apr 9
CVE-2026-1830: WordPress Quick Playground Plugin RCE via Unauthenticated File Upload
Apr 9
CVE-2026-25776: Movable Type Critical Code Injection (CVSS 9.8)
Apr 9
CVE-2026-39860: Nix Symlink Attack Allows Root File Overwrite
Apr 9
CVE-2026-39888: PraisonAI Sandbox Escape Enables Remote Code Execution
Apr 9
CVE-2026-39890: PraisonAI YAML Injection Achieves Remote Code Execution
Apr 9
CVE-2026-4498: Kibana Fleet Plugin Privilege Escalation Exposes Elasticsearch Index Data
Apr 8
13-Year-Old Bug in ActiveMQ Lets Hackers Remotely Execute Commands
Apr 8
Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems
Apr 8
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
Apr 8
FBI: Cybercrime Losses Neared $21 Billion in 2025
Apr 8
Hackers Use Pixel-Large SVG Trick to Hide Credit Card Stealer on Magento Stores
Apr 8
300,000+ Passport Numbers Leaked in December Eurail Data Breach
Apr 8
Snowflake Customers Hit in Data Theft Attacks After SaaS Integrator Breach
Apr 8
CVE-2021-4473: Tianxin Behavior Management System Unauthenticated Command Injection
Apr 8
CVE-2026-1340: Ivanti EPMM Code Injection Vulnerability
Apr 8
CVE-2026-20889: LibRaw x3f_thumb_loader Heap Buffer Overflow (CVSS 9.8)
Apr 8
CVE-2026-20911: LibRaw HuffTable::initval Heap Buffer Overflow (CVSS 9.8)
Apr 8
CVE-2026-21413: LibRaw lossless_jpeg_load_raw Heap Buffer Overflow (CVSS 9.8)
Apr 8
CVE-2026-22679: Weaver E-cology 10.0 Unauthenticated Remote Code Execution
Apr 8
CVE-2026-39397: PayloadCMS Puck Plugin Access Control Bypass
Apr 8
CVE-2026-4003: WordPress Users Manager PN Plugin Privilege Escalation (CVSS 9.8)
Apr 8
CVE-2026-5731: Firefox and Thunderbird Critical Memory Safety Vulnerabilities
Apr 8
Velociraptor DFIR: Endpoint Forensics and Incident Response at Scale
Apr 7
Authorities Disrupt APT28 Router DNS Hijacks Targeting Microsoft 365
Apr 7
China-Linked Storm-1175 Chains Zero-Days for High-Velocity Medusa Ransomware Attacks
Apr 7
Drift $280M Crypto Theft Linked to 6-Month In-Person DPRK Infiltration
Apr 7
FBI: Americans Lost a Record $21 Billion to Cybercrime Last Year
Apr 7
Hackers Exploit Critical Flaw in Ninja Forms WordPress Plugin
Apr 7
Medusa Ransomware Is Fast to Exploit Fresh Vulnerabilities and Breach Systems
Apr 7
Medusa Ransomware Exploits Zero-Days to Deploy Ransomware Within 24 Hours
Apr 7
Storm-1175 Deploys Medusa Ransomware at 'High Velocity'
Apr 7
The Hidden Cost of Recurring Credential Incidents
Apr 7
CVE-2026-1114: lollms JWT Weak Secret Key Allows Admin Takeover
Apr 7
CVE-2026-26026: GLPI Template Injection Enables Authenticated RCE via Admin Panel
Apr 7
CVE-2026-35392: Critical Path Traversal in goshs Go HTTP Server
Apr 7
CVE-2026-5637: SQL Injection in projectworlds Car Rental System 1.0
Apr 6
BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks
Apr 6
Disgruntled Researcher Leaks BlueHammer Windows Zero-Day Exploit
Apr 6
Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively Exploited With Full Patch Still Pending
Apr 6
German Authorities Identify REvil and GandCrab Ransomware Bosses Behind $40M in Damages
Apr 6
How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers
Apr 6
Medusa Ransomware Group Exploits Zero-Days to Strike Within 24 Hours
Apr 6
Microsoft Links Storm-1175 to Medusa Ransomware Zero-Day Campaign
Apr 6
GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables Full System Takeover
Apr 6
Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
Apr 6
Why Simple Breach Monitoring Is No Longer Enough
Apr 6
CVE-2019-25662: ResourceSpace 8.6 Unauthenticated SQL Injection
Apr 6
CVE-2026-5554: SQL Injection in Concert Ticket Reservation System Search
Apr 6
CVE-2026-5555: SQL Injection in Concert Ticket Reservation System Login
Apr 6
CVE-2026-5575: SQL Injection in SourceCodester Record Management System Login
Apr 6
Network Traffic Analysis with Zeek: From Deployment to Threat Detection
Apr 5
$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation
Apr 5
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
Apr 5
Black Hat USA 2026: What to Expect from the Year's Biggest Security Conference
Apr 5
Feds Disrupt IoT Botnets Behind Huge DDoS Attacks
Apr 5
Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
Apr 5
Germany Doxes "UNKN," Head of RU Ransomware Gangs REvil, GandCrab
Apr 5
Hackers Exploit React2Shell in Automated Credential Theft Campaign
Apr 5
New FortiClient EMS Flaw Exploited in Attacks, Emergency Patch Released
Apr 5
Traffic Violation Scams Switch to QR Codes in New Phishing Texts
Apr 5
Trump Budget Proposal Would Cut Hundreds of Millions More from CISA
Apr 5
CVE-2016-20052: Snews CMS 1.7 Unrestricted File Upload Allows Unauthenticated RCE
Apr 5
CVE-2026-5534 — SQL Injection in itsourcecode Online Enrollment System 1.0
Apr 5
CVE-2026-5540 — SQL Injection in code-projects Simple Laundry System 1.0
Apr 5
CVE-2026-5551: SQL Injection in itsourcecode Free Hotel Reservation System Login
Apr 4
Axios npm Hack Used Fake Teams Error Fix to Hijack Maintainer Account
Apr 4
Device Code Phishing Attacks Surge 37x as New Kits Spread Online
Apr 4
EU Cyber Agency Attributes Major Data Breach to TeamPCP Hacking Group
Apr 4
European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
Apr 4
Evolution of Ransomware: Multi-Extortion Ransomware Attacks
Apr 4
FCC Proposes $4.5 Million Fine for Voice Provider Hosting Suspicious Foreign Robocalls
Apr 4
Hims & Hers Warns of Data Breach After Zendesk Support Ticket Breach
Apr 4
Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers
Apr 4
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack
Apr 4
CVE-2017-20237: Hirschmann HiVision Auth Bypass Enables Unauthenticated RCE
Apr 4
CVE-2026-25197: IDOR Flaw Lets Authenticated Users Access Any Account Profile
Apr 4
CVE-2026-26477: DokuWiki media_upload_xhr() Denial of Service
Apr 4
CVE-2026-28766: Gardyn Smart Garden API Exposes All User Accounts Without Authentication
Apr 4
CVE-2026-3445: ProfilePress WordPress Plugin Allows Unauthorized Membership Payment Bypass
Apr 4
CVE-2026-35560: Amazon Athena ODBC Driver Fails Certificate Validation, Enabling MiTM Credential Theft
Apr 4
CVE-2026-4896: WCFM WooCommerce Plugin IDOR Allows Unauthorized Order Manipulation
Apr 3
250,000 Affected by Data Breach at Nacogdoches Memorial Hospital
Apr 3
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
Apr 3
CERT-EU: European Commission Hack Exposes Data of 30 EU Entities
Apr 3
Chainguard Unveils Factory 2.0 to Automate Hardening the Software Supply Chain
Apr 3
Claude Source Code Leak Highlights Big Supply Chain Missteps
Apr 3
Die Linke German Political Party Confirms Data Stolen by Qilin Ransomware
Apr 3
In Other News: ChatGPT Data Leak, Android Rootkit, Water Facility Hit by Ransomware
Apr 3
Microsoft Now Force-Upgrades Unmanaged Windows 11 24H2 PCs to 25H2
Apr 3
The Good, the Bad and the Ugly in Cybersecurity – Week 14
Apr 3
CVE-2026-26135: Azure Custom Locations SSRF Enables Privilege Escalation (CVSS 9.6)
Apr 3
CVE-2026-28815: swift-crypto X-Wing HPKE Out-of-Bounds Read
Apr 3
CVE-2026-33615: Critical Unauthenticated SQL Injection in setinfo Endpoint
Apr 2
Adversaries Exploit Vacant Homes to Intercept Mail in Hybrid Cybercrime
Apr 2
Cisco Patches Critical and High-Severity Vulnerabilities Across Product Lines
Apr 2
Claude Code Leak Used to Push Infostealer Malware on GitHub
Apr 2
Critical Vulnerability in Claude Code Emerges Days After Source Leak
Apr 2
Drift Crypto Platform Confirms $280 Million Stolen as Researchers Point to North Korea
Apr 2
Drift Loses $280 Million as Hackers Seize Security Council Powers
Apr 2
Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials
Apr 2
Mercor Confirms Security Incident Tied to LiteLLM Supply Chain Attack
Apr 2
New Progress ShareFile Flaws Can Be Chained in Pre-Auth RCE Attacks
Apr 2
Nissan Says Stolen Data Came from Third-Party Vendor After Hacking Group Claims Breach
Apr 2
Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE Attacks
Apr 2
The State of Trusted Open Source Report: Key Findings for 2025
Apr 2
CVE-2026-1540: Spam Protect CF7 WordPress Plugin PHP Log RCE
Apr 2
CVE-2026-31027: TOTOlink A3600R Buffer Overflow in setAppEasyWizardConfig
Apr 2
CVE-2026-3502: TrueConf Client Update Integrity Bypass Enables Arbitrary Code Execution
Apr 2
Juju Dqlite Cluster TLS Auth Bypass — Unauthenticated Database Access (CVE-2026-4370)
Apr 1
Apple Expands iOS 18 Updates to More iPhones to Block DarkSword Attacks
Apr 1
Axios NPM Package Breached in North Korean Supply Chain Attack
Apr 1
CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
Apr 1
Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms
Apr 1
Crypto Platform Drift Suspends Services After Hundreds of Millions Stolen
Apr 1
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069
Apr 1
Google Drive Ransomware Detection Now On by Default for Paying Users
Apr 1
Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in 2026
Apr 1
Hackers Exploit TrueConf Zero-Day to Push Malicious Software Updates
Apr 1
New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released
Apr 1
'NoVoice' Android Malware on Google Play Infected 2.3 Million Devices
Apr 1
CVE-2025-15618: Perl Payment Module Uses Insecure MD5/rand() Secret Key
Apr 1
CVE-2026-0596: MLflow Command Injection via Unsanitized model_uri (CVSS 9.6)
Apr 1
CVE-2026-1579: MAVLink Protocol Unauthenticated Shell Access
Apr 1
CVE-2026-34162: FastGPT Unauthenticated HTTP Proxy Enables Full SSRF (CVSS 10.0)
Apr 1
CVE-2026-5272: Chrome GPU Heap Buffer Overflow Enables Remote Code Execution
Apr 1
WireGuard Road Warrior VPN Server
March 2026
(234 articles)
Mar 31
Attack on Axios Developer Tool Threatens Widespread Compromises
Mar 31
Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account
Mar 31
CISA Orders Feds to Patch Actively Exploited Citrix Flaw by Thursday
Mar 31
Cisco Source Code Stolen in Trivy-Linked Dev Environment Breach
Mar 31
Claude AI Finds Vim and Emacs RCE Bugs That Trigger on File Open
Mar 31
Claude Code Source Code Accidentally Leaked in NPM Package
Mar 31
Dutch Finance Ministry Takes Treasury Banking Portal Offline After Breach
Mar 31
F5 BIG-IP Vulnerability Reclassified from DoS to RCE Under Active Exploitation
Mar 31
Google Slashes Quantum Resource Requirements for Breaking Cryptocurrency Encryption
Mar 31
Hacker Charged with Stealing $53 Million from Uranium Finance Crypto Exchange
Mar 31
Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations
Mar 31
Leak Bazaar: New Criminal Service Plans to Monetize Data Stolen by Ransomware Gangs
Mar 31
State Department Reissues $10 Million Reward for Info on Iranian Hackers
Mar 31
Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks
Mar 31
CVE-2026-31946: Critical JWT Signature Verification Bypass in OpenOlat E-Learning Platform
Mar 31
CVE-2026-32714: Critical SQL Injection in SciTokens KeyCache (CVSS 9.8)
Mar 30
Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks
Mar 30
Critical Fortinet FortiClient EMS Flaw Now Exploited in Attacks
Mar 30
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
Mar 30
European Commission Confirms Data Breach After Europa.eu Hack
Mar 30
Hackers Now Exploit Critical F5 BIG-IP Flaw in Attacks — Patch Now
Mar 30
Healthcare Software Firm CareCloud Informs SEC of Potential Patient Data Leak
Mar 30
Healthcare Tech Firm CareCloud Says Hackers Stole Patient Data
Mar 30
Italian Regulator Fines Financial Giant $36 Million for Data Protection Failures
Mar 30
New RoadK1ll WebSocket Implant Used to Pivot on Breached Networks
Mar 30
The State of Secrets Sprawl 2026: 9 Takeaways for CISOs
Mar 30
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign
Mar 30
Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Mar 30
CVE-2025-15036: MLflow Path Traversal in Archive Extraction
Mar 30
CVE-2025-15379: MLflow Command Injection in Model Serving (CVSS 10.0)
Mar 30
CVE-2026-2370: GitLab Jira Connect Credential Impersonation
Mar 30
CVE-2026-32973: OpenClaw Exec Allowlist Bypass via Glob Wildcard Overmatch
Mar 30
CVE-2026-32975: OpenClaw Zalouser Weak Authorization via Mutable Group Display Names
Mar 30
CVE-2026-32987: OpenClaw Bootstrap Code Replay Enables Privilege Escalation to operator.admin
Mar 30
CVE-2026-4176: Perl Compress::Raw::Zlib Critical Vulnerability (CVSS 9.8)
Mar 30
CVE-2026-5128: Steam Trader 2.1.1 Unauthenticated Sensitive Data Exposure
Mar 30
Suricata IDS/IPS Deployment: From Install to Active Threat Detection
Mar 29
AI Slashes Cyberattack Exploit Timelines From Years to Days
Mar 29
CISA: New Langflow Flaw Actively Exploited to Hijack AI Workflows
Mar 29
Dutch Court Threatens xAI with Fines Over Grok's Nonconsensual Nude Images
Mar 29
European Parliament Rejects Extension of CSAM Scanning Rules for Tech Platforms
Mar 29
FBI Confirms Hack of Director Patel's Personal Email Inbox
Mar 29
FCC Bans Import of Foreign-Made Consumer Routers Over Supply Chain Security Risks
Mar 29
File Read Flaw in Smart Slider Plugin Impacts 500K WordPress Sites
Mar 29
Foster City Declares State of Emergency After Ransomware Cripples Municipal Services
Mar 29
ShinyHunters Breach Infinite Campus — K-12 Platform Serving 11 Million Students
Mar 29
CVE-2016-20049: JAD Java Decompiler Stack-Based Buffer Overflow Enables Arbitrary Code Execution
Mar 29
CVE-2017-20225: TiEmu TI Calculator Emulator Stack Buffer Overflow Allows Arbitrary Code Execution via Command-Line Arguments
Mar 29
CVE-2026-32922: OpenClaw Privilege Escalation via Token Scope Bypass
Mar 29
CVE-2026-32924: OpenClaw Authorization Bypass via Feishu Chat Misclassification
Mar 29
CVE-2026-5016: elecV2P SSRF Vulnerability in URL Handler Allows Remote Attack
Mar 29
CVE-2026-5017: SQL Injection in code-projects Simple Food Order System (Tickets)
Mar 29
CVE-2026-5018: SQL Injection in code-projects Simple Food Order System (Register)
Mar 29
CVE-2026-5019: SQL Injection in code-projects Simple Food Order System (Orders)
Mar 29
CVE-2026-5033: SQL Injection in code-projects Accounting System (Customer View)
Mar 29
CVE-2026-5034: SQL Injection in code-projects Accounting System 1.0
Mar 28
Anti-Piracy Coalition Takes Down AnimePlay App with 5 Million Users
Mar 28
Backdoored Telnyx PyPI Package Pushes Malware Hidden in WAV Audio
Mar 28
Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware
Mar 28
CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
Mar 28
Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active Reconnaissance
Mar 28
Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
Mar 28
Iran-Linked Hackers Breach FBI Director's Personal Email, Hit Stryker With Wiper Attack
Mar 28
New Infinity Stealer Malware Grabs macOS Data via ClickFix Lures
Mar 28
TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
Mar 28
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files
Mar 28
CVE-2025-12886: Oxygen Theme SSRF Allows Unauthenticated Web Requests
Mar 28
CVE-2026-27856: Dovecot doveadm Timing Oracle Enables Credential Recovery
Mar 28
CVE-2026-27876 — Grafana Critical RCE via SQL Expression Chain
Mar 28
CVE-2026-30303 — Axon Code OS Command Injection via Whitelist Bypass
Mar 28
CVE-2026-30304 — AI Code Safe Command Execution Bypass
Mar 28
CVE-2026-33875: Gematik Authenticator Authentication Flow Hijacking (CVSS 9.3)
Mar 27
European Commission Investigating Breach After Amazon Cloud Account Hack
Mar 27
CVE-2025-53521: F5 BIG-IP APM Remote Code Execution — CISA KEV (CVSS 9.8)
Mar 27
CVE-2026-33669: SiYuan Unauthenticated Document Content Exposure (CVSS 9.8)
Mar 27
CVE-2026-33670: SiYuan readDir Path Traversal Notebook Enumeration (CVSS 9.8)
Mar 27
Container Security Scanning with Trivy: Images, IaC, and CI/CD
Mar 27
Build a Collaborative IPS with CrowdSec
Mar 26
PolyShell Attacks Target 56% of All Vulnerable Magento Stores
Mar 26
Pro-Ukraine Hacker Group Bearlyfy Targets Russian Companies with Custom Ransomware
Mar 26
Russia Detains Alleged Admin of LeakBase Cybercrime Forum Weeks After Global Crackdown
Mar 26
WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
Mar 26
HashiCorp Vault: Centralized Secrets Management for Modern Infrastructure
Mar 26
Keycloak SSO: Self-Hosted Identity Provider for Your Homelab
Mar 25
Citrix Urges Admins to Patch NetScaler Flaws as Soon as Possible
Mar 25
DarkSword GitHub Leak Threatens to Turn Elite iPhone Hacking Into a Tool for the Masses
Mar 25
LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace
Mar 25
Manager of Botnet Used in Ransomware Attacks Gets 2 Years in Prison
Mar 25
Paid AI Accounts Are Now a Hot Underground Commodity
Mar 25
PTC Warns of Imminent Threat from Critical Windchill, FlexPLM RCE Bug
Mar 25
Supply Chain Attack Hits Widely-Used AI Package, Risking Thousands of Companies
Mar 25
CVE-2026-27651 — NGINX ngx_mail_auth_http_module NULL Pointer Dereference
Mar 24
3.1 Million Impacted by QualDerm Partners Data Breach
Mar 24
Hacker Walks Away with $24.5 Million After Breaching Resolv DeFi Platform
Mar 24
Russian Hacker Who Helped Yanluowang Ransomware Gang Gets Nearly 7-Year Prison Sentence
Mar 24
CVE-2026-33478: AVideo CloneSite Plugin Unauthenticated RCE (CVSS 10.0)
Mar 23
Crunchyroll Probes Breach After Hacker Claims to Steal 6.8M Users' Data
Mar 23
Mazda Discloses Security Breach Exposing Employee and Partner Data
Mar 23
Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper
Mar 23
Trivy Supply Chain Attack Targets CI/CD Secrets
Mar 23
US Sentences Nigerian National to 7 Years in $6 Million Email Fraud Scheme
Mar 23
Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Mar 23
Tenda A15 UploadCfg Stack Buffer Overflow (CVE-2026-4567)
Mar 23
CVE-2026-4599: jsrsasign Private Key Recovery via DSA Nonce Bias (CVSS 9.1)
Mar 22
CanisterWorm: First Blockchain-Powered Self-Spreading Worm Hits 47 npm Packages
Mar 22
Cegedim Santé Breach Exposes 15.8 Million French Healthcare Records Including HIV Status
Mar 22
CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog
Mar 22
FBI Warns Russian Intelligence Targeting Signal and WhatsApp in Mass Phishing Campaign
Mar 22
Malaysia Airlines Listed by Qilin Ransomware Group — Passenger Data at Risk
Mar 22
Trivy Vulnerability Scanner Breached to Push Infostealer via GitHub Actions
Mar 22
VoidStealer Malware Steals Chrome Master Key via Debugger Trick
Mar 22
CVE-2026-3629: WordPress User Import Plugin Privilege Escalation
Mar 22
D-Link DHP-1320 SOAP Handler Stack Buffer Overflow (CVE-2026-4529)
Mar 21
Two US Cybersecurity Professionals Plead Guilty to BlackCat Ransomware Attacks
Mar 21
Interlock Ransomware Exploited Cisco FMC Zero-Day for 36 Days Before Disclosure
Mar 21
Critical Langflow RCE Flaw Exploited Within 20 Hours of Disclosure
Mar 21
Marquis Fintech Breach Exposes 672,000 Banking Customers via SonicWall Exploit
Mar 21
New Speagle Malware Hijacks Cobra DocGuard for State-Sponsored Espionage
Mar 21
CVE-2025-43510: Apple Multiple Products Improper Locking Vulnerability
Mar 21
CVE-2025-54068: Laravel Livewire Code Injection Vulnerability
Mar 21
CVE-2026-22172: OpenClaw Critical Authorization Bypass via WebSocket Scope Elevation
Mar 20
DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
Mar 20
Eclypsium Raises $25 Million to Expand Device Supply Chain Security Platform
Mar 20
Navia Data Breach Impacts 2.7 Million People
Mar 20
Navia Discloses Data Breach Impacting 2.7 Million People
Mar 20
Oracle Pushes Emergency Fix for Critical Identity Manager RCE Flaw
Mar 20
Trivy Security Scanner GitHub Actions Breached — 75 Tags Hijacked to Steal CI/CD Secrets
Mar 20
CVE-2025-32432: Craft CMS Code Injection Vulnerability
Mar 20
CVE-2026-21992: Critical Oracle Identity Manager Unauthenticated RCE via REST WebServices
Mar 20
CVE-2026-30836: Step CA SCEP UpdateReq Allows Unauthenticated Certificate Issuance (CVSS 10)
Mar 20
CVE-2026-32238: Critical Command Injection in OpenEMR Backup Functionality
Mar 19
CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC Zero-Day Tied to Ransomware
Mar 19
CVE-2026-25449: Critical Object Injection in Shinetheme Traveler WordPress Plugin
Mar 18
Cloud Security Startup Native Exits Stealth With $42 Million to Enforce Security-by-Design Across Multi-Cloud
Mar 18
Critical Unpatched GNU Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE
Mar 18
Marquis Ransomware Breach: 672K People Exposed as Attack Disrupts 80 US Banks
Mar 18
Interlock Ransomware Has Been Exploiting Cisco FMC Zero-Day CVE-2026-20131 Since January
Mar 18
Shadow AI in SaaS: How Hidden AI Agents Are Enabling Catastrophic Breaches
Mar 18
CVE-2026-21994: Critical Unauthenticated RCE in Oracle Edge Cloud Infrastructure Designer v0.3.0
Mar 18
CVE-2026-25534: Spinnaker SSRF via URL Validation Bypass Using Java Underscore Parsing Bug
Mar 18
CVE-2026-25769: Wazuh Critical RCE via Insecure Deserialization in Cluster Protocol
Mar 18
CVE-2026-25770: Wazuh Privilege Escalation to Root via Cluster Protocol File Write
Mar 18
CVE-2026-30884: Critical Authorization Bypass in Moodle mod_customcert Plugin (CVSS 9.6)
Mar 18
CVE-2026-32298: Angeet ES3 KVM OS Command Injection via cfg.lua Script
Mar 18
CVE-2026-3564: ConnectWise ScreenConnect Auth Bypass via Server Cryptographic Material
Mar 17
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE
Mar 17
LeakNet Ransomware Weaponizes ClickFix and Deno Runtime for Stealthy Corporate Attacks
Mar 17
Microsoft Shares Fix for Windows C: Drive Access Issues on Samsung PCs
Mar 17
Microsoft Halts Forced Global Rollout of Microsoft 365 Copilot App
Mar 17
CVE-2015-20118: Stored XSS in RealtyScript 4.0.2 Admin Interface
Mar 17
CVE-2025-62319: Critical SQL Injection in HCL Unica (CVSS 9.8)
Mar 17
CVE-2025-69902: Critical Command Injection in kubectl-mcp-server
Mar 17
CVE-2026-4177: YAML::Syck Heap Buffer Overflow Enables Remote Code Execution
Mar 17
CVE-2026-4312: DrangSoft GCB/FCB Audit Software Missing Authentication Allows Unauthenticated Admin Account Creation
Mar 16
Android 17 Blocks Non-Accessibility Apps from Accessibility API to Prevent Malware Abuse
Mar 16
CISA Adds Wing FTP Server Flaw to KEV as RCE Chain Exploits Surge
Mar 16
GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison Hundreds of Python Repos
Mar 16
Shadow AI Is Everywhere. Here's How to Find and Secure It.
Mar 16
Stryker Cyberattack Wiped Tens of Thousands of Devices — No Malware Needed
Mar 16
Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents
Mar 16
CVE-2015-20115: RealtyScript 4.0.2 Stored XSS via File Upload in Admin Panel
Mar 16
CVE-2016-20024: ZKTeco ZKTime.Net Insecure File Permissions Allow Privilege Escalation
Mar 16
CVE-2016-20026: ZKTeco ZKBioSecurity 3.0 Hardcoded Tomcat Credentials Allow Unauthenticated RCE
Mar 16
CVE-2016-20030: ZKTeco ZKBioSecurity 3.0 Username Enumeration via Login Endpoint
Mar 16
CVE-2025-47813: Wing FTP Server Path Disclosure Enables RCE Chain
Mar 16
How to Deploy Falco for Kubernetes Runtime Security Monitoring
Mar 15
Betterleaks: New Open-Source Secrets Scanner Built to Replace Gitleaks
Mar 15
Windows 11 February Update Breaks C:\ Drive Access on Samsung PCs
Mar 15
OpenAI Says ChatGPT Ads Are Not Rolling Out Globally For Now
Mar 15
Operation Synergia III: Police Sinkhole 45,000 IPs in Global Cybercrime Crackdown
Mar 14
AppsFlyer Web SDK Supply Chain Attack Spread
Mar 14
GlassWorm Escalates: 72 Malicious Open VSX Extensions Use
Mar 14
Microsoft Releases Windows 11 OOB Hotpatch to Fix Three
Mar 14
OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click
Mar 13
England Hockey Investigating Data Breach After AiLock
Mar 13
Telus Digital Confirms Massive Breach After ShinyHunters
Mar 13
Veeam Patches Five Critical RCE Vulnerabilities Exposing
Mar 13
Critical RCE in Veeam Backup & Replication — Authenticated
Mar 13
Critical RCE in Veeam Backup & Replication — Authenticated
Mar 13
Critical RCE in Veeam Backup & Replication — Third Domain
Mar 13
Critical RCE in Veeam Backup & Replication HA Deployments
Mar 13
Critical RCE in Veeam Backup & Replication — Backup Viewer
Mar 13
Critical CORS + Path Traversal in TinaCMS CLI Dev Server
Mar 13
How to Deploy Wazuh SIEM/XDR for Unified Security Monitoring
Mar 13
HashiCorp Vault: Secrets Management for Your Homelab and
Mar 12
CISA Flags Actively Exploited n8n RCE Bug as 24,700
Mar 12
CISA Orders Federal Agencies to Patch n8n RCE Flaw
Mar 12
Researchers Disclose Critical n8n Flaws Enabling RCE and
Mar 12
CVE-2025-68613: n8n Remote Code Execution via Improper
Mar 11
UNC6426 Weaponizes Old nx npm Supply Chain Compromise to
Mar 11
The Zero-Day Scramble Is Avoidable: Why Attack Surface
Mar 11
Critical RCE in Hitachi Vantara Pentaho via Unrestricted
Mar 11
Critical Auth Bypass in Tutor LMS Pro Exposes 30,000+
Mar 11
Claude Code for IT Operations: Building a Multi-Project
Mar 11
Securing AI-Assisted Development with Claude Code
Mar 11
Application Deployment Security Checklist
Mar 11
Backup & Disaster Recovery Checklist
Mar 11
Microsoft 365 Tenant Security Checklist
Mar 11
Network Security Audit Checklist
Mar 11
Vulnerability Management Checklist
Mar 10
CVE-2026-3038: FreeBSD Kernel Stack Buffer Overflow in
Mar 9
Ericsson US Discloses Data Breach Affecting Employees and
Mar 9
ShinyHunters Claims Mass Data Theft From 400 Firms via
Mar 9
North Korea's UNC4899 Breached Crypto Firm via AirDropped
Mar 9
Critical Stack-Based Buffer Overflow in Delta Electronics
Mar 9
CVE-2026-3730: SQL Injection in itsourcecode Free Hotel
Mar 9
CVE-2026-3734: Improper Authorization in SourceCodester
Mar 9
CVE-2026-3740: SQL Injection in itsourcecode University
Mar 9
CVE-2026-3746: SQL Injection in SourceCodester Simple
Mar 9
How to Secure GitHub Actions Workflows with OIDC, SHA
Mar 9
How to Configure Microsoft Sentinel Analytics Rules
Mar 8
Termite Ransomware Operator Velvet Tempest Chains ClickFix
Mar 8
CVE-2026-29067: ZITADEL Password Reset Poisoned by
Mar 8
ZITADEL Critical XSS in SAML Endpoint Enables 1-Click
Mar 8
CVE-2026-29192: ZITADEL Stored XSS via Default Redirect URI
Mar 7
Cognizant TriZetto Breach Exposes Health Data of 3.4
Mar 7
CVE-2018-25165: SQL Injection Vulnerability Disclosed in
Mar 7
CVE-2018-25169: Denial of Service Vulnerability Catalogued
Mar 7
CVE-2026-3589: WooCommerce CSRF Flaw Allows Unauthenticated
Mar 6
Google: 90 Zero-Days Exploited in 2025 — Enterprise Tech
Mar 6
Spanish-Ukrainian Police Bust Gambling Ring That Exploited
Mar 6
Microsoft Entra PIM: Configuring Just-in-Time Admin Access
Mar 6
Deception Technology Lab: T-Pot Honeypot with OpenCanary
Mar 5
Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims
Mar 4
Cloudflare 2026 Threat Report: 230 Billion Daily Threats as
Mar 4
Europol-Coordinated Action Dismantles Tycoon2FA — 330
Mar 4
LexisNexis Confirms Cloud Breach Exposing 400K User
Mar 4
CISA Issues Emergency Directive as Cisco SD-WAN Zero-Day
Mar 4
CVE-2026-28775: Unauthenticated Root RCE in IDC SFX
Mar 4
Mail2Shell: Zero-Click RCE in FreeScout Helpdesk
Mar 4
CISA Adds Actively Exploited VMware Aria Operations RCE
Mar 3
Android March 2026 Security Update Patches 129
Mar 2
Operation Epic Fury Triggers Unprecedented Cyber Escalation
Mar 1
Former Cybersecurity Incident Responders Plead Guilty to
February 2026
(234 articles)
Feb 28
Google Disrupts Massive Chinese Espionage Campaign
Feb 28
Iran Plunged Into Digital Darkness: Internet Drops to 4% in
Feb 27
Leaked Documents Reveal China's 'Expedition Cloud' Cyber
Feb 27
IDMerit KYC Data Breach Exposes 1 Billion Records Across 26
Feb 26
Cisco SD-WAN Zero-Day CVE-2026-20127 Triggers Five Eyes
Feb 25
AI-Armed Amateur Hacker Compromises 600+ FortiGate
Feb 25
Diesel Vortex: Russian Cybercrime Ring Steals 1,649
Feb 25
The World's First Transatlantic Fiber Cable Is Being Pulled
Feb 25
Ransomware Forces University of Mississippi Medical Center
Feb 25
Microsoft MSHTML Framework Security Feature Bypass
Feb 25
Microsoft Office Word OLE Security Feature Bypass
Feb 25
Soliton FileZen OS Command Injection Under Active
Feb 24
Japanese Semiconductor Giant Advantest Hit by Ransomware
Feb 24
Anthropic Exposes Industrial-Scale AI Distillation Attacks
Feb 24
APT28 Operation MacroMaze: Russia-Linked Hackers Hit
Feb 24
AT&T Breach Data Resurfaces: 176 Million Records with Fully
Feb 24
CrowdStrike 2026 Threat Report: eCrime Breakout Time Falls
Feb 24
U.S. Treasury Sanctions Russian Zero-Day Broker Operation
Feb 23
HellCat Ransomware Group Breaches Ascom, Exfiltrates 44GB
Feb 23
Cline CLI Supply Chain Attack Installs Unauthorized
Feb 23
CISA Adds Two Actively Exploited Roundcube Webmail Flaws to
Feb 23
How to Detect and Block ClickFix Attacks
Feb 23
Domain Controller Hardening: Securing Active Directory
Feb 23
FortiGate Performance Optimization: Tuning Guide for
Feb 23
FortiGate Security Hardening: Best Practices for Enterprise
Feb 23
How to Set Up BGP Monitoring and Route Alerts
Feb 23
Windows Server Hardening: Complete Security Guide for
Feb 23
Endpoint Security Baseline: Windows 11 + Intune
Feb 23
IT Employee Offboarding Checklist
Feb 20
CISA Loses 62% of Workforce as DHS Shutdown Guts America's
Feb 20
Fintech Giant Figure Technology Confirms Breach: Nearly 1
Feb 20
ShinyHunters Dumps Harvard and UPenn Data After Ransom
Feb 20
Japan Airlines Confirms Data Breach Affecting 28,000
Feb 20
Persona Source Code Leak Exposes Hidden Biometric
Feb 20
PromptSpy: First Android Malware to Weaponize Generative AI
Feb 20
Pro-Russian Hacktivists Launch Sustained Cyber Campaign
Feb 20
WormGPT Hacked: 19,000 Cybercriminal AI Platform Users
Feb 20
BeyondTrust Remote Support and PRA Critical RCE Under
Feb 20
Google Patches First Chrome Zero-Day of 2026: CVE-2026-2441
Feb 20
Microsoft February 2026 Patch Tuesday Fixes Six Actively
Feb 20
Critical RCE in Microsoft Semantic Kernel Python SDK
Feb 19
WEF Global Cybersecurity Outlook 2026 Warns of 'Permanent
Feb 19
Conduent Breach Balloons to Tens of Millions of Americans
Feb 19
Hacker Accesses 1.2 Million French Bank Accounts via
Feb 19
International AI Safety Report 2026 Warns of AI-Driven
Feb 18
AI-Driven Threats Accelerate: Agentic Attacks, Model
Feb 18
Notepad++ Supply Chain Attack Attributed to China-Linked
Feb 18
Dell RecoverPoint Zero-Day Exploited by Chinese APT Since
Feb 18
Critical Grandstream VoIP Vulnerability Allows
Feb 17
Scattered Lapsus$ ShinyHunters Alliance Hits 100+
Feb 17
Adani Pledges $100 Billion for Renewable-Powered AI Data
Feb 17
Alibaba Launches Qwen 3.5 — Claims to Outperform GPT-5.2
Feb 17
ETH Zurich Finds 25 Password Recovery Attacks Against
Feb 17
Microsoft Discovers 'AI Recommendation Poisoning' via
Feb 17
Nova (RALord) Ransomware Group Confirmed Active with 73
Feb 17
Reynolds Ransomware Embeds BYOVD Driver to Disable EDR
Feb 17
Warlock Ransomware Breaches SmarterTools via Its Own
Feb 17
Trojanized MCP Server Deploys StealC Infostealer Targeting
Feb 17
UK Brings AI Chatbots Under Online Safety Act — Fines Up to
Feb 17
YouTube Suffers Major Global Outage Affecting 300,000+ Users
Feb 17
ZeroDayRAT Mobile Spyware Enables Total Surveillance of iOS
Feb 17
Apple Patches Actively Exploited iOS Zero-Day Used in
Feb 17
BeyondTrust Remote Support Pre-Authentication RCE Under
Feb 17
Cisco Unified Communications Zero-Day Exploited for
Feb 16
Anthropic Hits $380 Billion Valuation After Closing $30
Feb 16
APT28 Weaponizes Microsoft Office Zero-Day in 3 Days
Feb 16
ShinyHunters Dumps 600K+ Canada Goose Customer Records on
Feb 16
Cloudflare BGP Routing Error Cascades Across AWS, X, and
Feb 16
India Hosts Global AI Impact Summit — 20 World Leaders and
Feb 16
Google Chrome Use-After-Free Zero-Day Under Active
Feb 16
Ivanti EPMM Zero-Days Breach Dutch, EU, and Finnish
Feb 15
Ransomware in 2026: Data-Only Extortion Replaces Encryption
Feb 15
Russian APT 'ChainReaver' Hijacks 50 GitHub Accounts and
Feb 15
ClickFix Attacks Evolve — Now Abusing DNS nslookup for
Feb 15
GitHub Copilot Command Injection Flaws Enable Remote Code
Feb 14
FBI Warns of ATM Jackpotting Surge as Losses Top $20
Feb 14
Claude AI Artifacts Abused to Distribute macOS Infostealer
Feb 13
AI Chat App Exposes 300 Million Private Messages from 25
Feb 13
Malicious Chrome Extension 'CL Suite' Steals Meta Business
Feb 13
ClickFix Campaign Targets European Hotels with Fake
Feb 13
All Four Major Nation-State Adversaries Now Weaponizing
Feb 13
Odido Data Breach Exposes 6.2 Million Dutch Telecom
Feb 13
Russian-Linked CANFAIL Malware Targets Ukrainian Defense
Feb 13
Truebit Protocol Hit by $26.5 Million DeFi Hack via Smart
Feb 12
IRS Shares Tax Data of 1.28 Million Individuals with DHS
Feb 12
Romania's National Oil Pipeline Operator Conpet Hit by
Feb 12
Lazarus Group Plants 192 Malicious Packages in npm and PyPI
Feb 12
Louis Vuitton, Dior, and Tiffany Fined $25 Million Over
Feb 12
Ransomware Attacks Surge 49% Year-Over-Year: BlackFog 2026
Feb 12
Apple Patches Actively Exploited Zero-Day in dyld
Feb 12
Critical RCE in WPvivid Backup Plugin Threatens 900,000+
Feb 11
Ex-L3Harris Executive Pleads Guilty to Selling Eight
Feb 11
2026 Vulnerability Forecast: Up to 117,000 CVEs Expected
Feb 11
6.8 Billion Emails Exposed Online in Massive Data Leak
Feb 11
North Korea Deploys AI-Generated Video and ClickFix
Feb 11
Ransomware Costs Projected to Hit $74 Billion in 2026, 30%
Feb 11
SSHStalker Linux Botnet Uses IRC Protocol for Command and
Feb 11
Microsoft Patch Tuesday February 2026: 6 Actively Exploited
Feb 11
CVE-2026-21533: Windows Remote Desktop Services Zero-Day
Feb 11
SentinelOne Health Check: Agent Status Monitoring and
Feb 11
Deploy SentinelOne Policy
Feb 11
Invoke SentinelOne Threat Hunt
Feb 11
SentinelOne Application Control Policies
Feb 11
SentinelOne Control vs Complete Feature Comparison
Feb 11
SentinelOne Create and Manage Exclusion Policies
Feb 11
SentinelOne Data Retention and Storage Management
Feb 11
SentinelOne Deep Visibility Threat Hunting
Feb 11
SentinelOne Deploy Agent Manual Installation
Feb 11
SentinelOne Deploy Agent via Group Policy
Feb 11
SentinelOne Device Control Configuration
Feb 11
SentinelOne File Fetch and Forensic File Collection
Feb 11
SentinelOne Firewall Control Management
Feb 11
SentinelOne Forensics Rollback and Remediation
Feb 11
SentinelOne MITRE ATT&CK Threat Hunting
Feb 11
SentinelOne MSP Client Onboarding
Feb 11
SentinelOne Policy Configuration Best Practices
Feb 11
SentinelOne PowerShell API Automation
Feb 11
SentinelOne PowerShell Automation Scripts
Feb 11
SentinelOne Purple AI Usage Guide
Feb 11
SentinelOne Ranger Network Discovery and IoT Visibility
Feb 11
SentinelOne Remote Shell Operations
Feb 11
SentinelOne RMM Integration Guide
Feb 11
SentinelOne Sandbox Integration Configuration
Feb 11
SentinelOne STAR Advanced Automation and Watchlists
Feb 11
SentinelOne STAR Custom Detection Rules
Feb 11
SentinelOne Threat Investigation Workflow
Feb 11
SentinelOne Timeline Forensics and Attack Chain Analysis
Feb 11
IT Employee Onboarding Checklist
Feb 10
Google's $32 Billion Wiz Acquisition Clears Final Hurdle as
Feb 10
BridgePay Payment Gateway Knocked Offline by Ransomware
Feb 10
China-Linked UNC3886 Breaches All Four Singapore Telecom
Feb 10
EU Launches NanoIC, Europe's Largest Chips Act Pilot Line
Feb 10
Gartner Identifies the Top 6 Cybersecurity Trends Reshaping
Feb 10
Microsoft Hit by Back-to-Back Outages: M365 Admin Center
Feb 10
OpenAI Launches Frontier Enterprise Agent Platform and
Feb 10
BeyondTrust Zero-Day Allows Unauthenticated Command
Feb 10
Lotus Blossom APT Compromises Notepad++ Updates to Deploy
Feb 10
UNC3886 Zero-Day Campaign: Singapore Telecom Operators
Feb 10
Windows SmartScreen Bypass Under Active Exploitation
Feb 10
WinRAR Path Traversal Flaw CVE-2025-8088 Actively Exploited
Feb 10
Building Offline-First PWAs with Next.js and SQLite
Feb 10
Server Hardening Security Checklist
Feb 9
Massive Kimwolf Botnet Disrupts I2P Anonymous Network
Feb 9
VoidLink: AI-Generated Cloud-Native Malware Framework
Feb 9
Critical PAN-OS GlobalProtect Gateway RCE Vulnerability
Feb 9
Active Directory Health Check: Comprehensive Diagnostic
Feb 9
Building Event-Driven Systems with Python asyncio
Feb 9
Build an Active Directory Penetration Testing Lab
Feb 9
Incident Response Checklist
Feb 8
FBI Warns of AI-Generated Deepfake Phishing Targeting
Feb 8
Tirith: New Open-Source Tool Blocks Homoglyph Attacks
Feb 8
North Korean Hackers Use Fake Zoom Meeting to Target Crypto
Feb 8
International AI Safety Report: AI Now Provides 'Meaningful
Feb 8
Cisco IOS XE Web UI Privilege Escalation Actively Exploited
Feb 8
Configuring Windows LAPS: Automated Local Admin Password
Feb 8
Multi-Stack Docker Infrastructure with Traefik and
Feb 8
Cloud Migration Readiness Checklist
Feb 7
CISA Mandates Full Zero Trust Architecture for Federal
Feb 7
Shadow Campaigns: State-Backed Espionage Group Breaches 70+
Feb 7
Fortinet FortiOS SSL VPN Heap Overflow Enables Pre-Auth RCE
Feb 7
Eight Critical n8n Vulnerabilities — Sandbox Escape to
Feb 7
Automating Report Generation with Python and Jinja2
Feb 7
Nmap Scanning Techniques for Security Professionals
Feb 7
Build a Dedicated OSINT Investigation Workstation
Feb 6
Cyberattacks on Critical Infrastructure Double in Q1 2026
Feb 6
DKnife: China-Linked AitM Framework Hijacks Router Traffic
Feb 6
Apache Struts Critical RCE via OGNL Injection Returns
Feb 6
Critical Fortinet FortiClientEMS SQL Injection
Feb 6
IPTV Stream Validation and M3U Playlist Management with
Feb 6
OSINT Reconnaissance Methodology for Security Professionals
Feb 5
ShinyHunters Dumps 5.1 Million Panera Bread Customer
Feb 5
Substack Discloses Data Breach After 100-Day Undetected
Feb 5
Amazon Alexa+ Goes GA After Tens of Millions Join Beta
Feb 5
Google Begins Post-Quantum Cryptography Rollout Across
Feb 5
Samsung Ends Software Support for Galaxy S21 Series
Feb 5
SpaceX-xAI Partnership Values Combined Entities Near $1.25
Feb 5
Conduent Breach Expands: 15.4 Million Texans Affected, 8TB
Feb 5
Iron Mountain Responds to Everest Ransomware Breach Claims
Feb 5
Microsoft Exchange Server SSRF to RCE Chain Actively
Feb 5
NGINX TLS Vulnerability Enables Man-in-the-Middle Attacks
Feb 5
SolarWinds Web Help Desk RCE Vulnerability Added to CISA KEV
Feb 5
Building Desktop Apps with Electron and Next.js
Feb 5
Microsoft 365 Security and Compliance Configuration Guide
Feb 5
Microsoft 365 Security Baseline Implementation
Feb 4
AI-Powered Cyberattacks Expected to Cause Major Enterprise
Feb 4
Google Chrome Critical Update Patches High-Severity Code
Feb 4
The Rise of Ransomware-as-a-Service: 14 Active Platforms
Feb 4
Ransomware Attacks Surge in Early 2026 with 26 Claims in
Feb 4
CISA Adds Four Critical Vulnerabilities to KEV Catalog
Feb 4
Critical Google Looker Vulnerabilities Allow Full System
Feb 4
Critical n8n Vulnerability (CVSS 10.0) Enables Complete
Feb 4
Group Policy Security Hardening for Windows Environments
Feb 4
IT Service Dashboards with PowerShell Universal
Feb 3
Senator Demands AT&T, Verizon CEOs Testify Over Salt
Feb 3
AWS Security Hub: Centralized Security Findings
Feb 3
Azure Backup: VMs, Files, and SQL with Recovery Services
Feb 3
Business Central Docker Containers: Development Environment
Feb 3
Security Baseline Hardening: CIS Controls Implementation
Feb 3
Conditional Access Policies: Zero Trust with Entra ID
Feb 3
Microsoft Defender for Endpoint: Configuration and
Feb 3
Docker Windows Containers: Native Engine Setup Guide
Feb 3
Enterprise BitLocker Automation with PowerShell
Feb 3
Exchange Online Security Hardening for Enterprise
Feb 3
FortiAnalyzer Log Forwarding and Compliance Reports
Feb 3
FortiGate Firewall Policy Management with PowerShell
Feb 3
FortiGate IPsec VPN: Site-to-Site with Azure
Feb 3
FortiGate SSL VPN Setup: Secure Remote Access Configuration
Feb 3
Incident Response Playbook: Ransomware
Feb 3
Intune Device Enrollment: Windows Autopilot Setup
Feb 3
Kubernetes Network Policies: Microsegmentation Guide
Feb 3
Kubernetes Secrets Management with External Secrets Operator
Feb 3
Automated News Aggregation with Deduplication Algorithms
Feb 3
NinjaOne Scripting: PowerShell Automation Library
Feb 3
SentinelOne Agent Deployment: EDR Installation and
Feb 3
SentinelOne Threat Hunting with Deep Visibility
Feb 3
Azure Landing Zone with Terraform
Feb 3
Azure Sentinel SIEM Implementation
Feb 3
Building a RAG System Without ML Embeddings
Feb 3
CI/CD Pipeline with GitHub Actions and Azure
Feb 3
Cove Data Protection Implementation
Feb 3
FortiGate SD-WAN Deployment
Feb 3
Fortinet Centralized Management with FortiManager &
Feb 3
Homelab Media Server with Full ARR Stack
Feb 3
Kubernetes Homelab Cluster with K3s
Feb 3
Network Traffic Analysis with Zeek and Suricata
Feb 3
NinjaOne RMM Platform Setup
Feb 3
SentinelOne Complete Deployment Guide
Feb 2
Critical Vulnerability Discovered in Popular Enterprise VPN
Feb 2
Building a Secure Homelab in 2026: Complete Guide
Feb 2
Building PWAs with IndexedDB for Offline Data
Feb 2
Python for Security Automation: Essential Scripting
Feb 1
Microsoft Announces Major Security Features for Copilot
Feb 1
Building a Content Platform with Next.js 16 and
Feb 1
Build Your Own SIEM with Open-Source Tools
January 2026
(32 articles)
Jan 30
Cisco Patches Critical Webex Vulnerability Allowing Remote
Jan 28
Record-Breaking 31.4 Tbps DDoS Attack: Aisuru Botnet Sets
Jan 28
SSH Hardening Best Practices
Jan 28
WireGuard VPN Setup: Secure Remote Access
Jan 27
Healthcare Sector Faces Unprecedented Ransomware Surge in
Jan 26
Linux Server Hardening: Complete Security Checklist
Jan 25
WordPress Plugin Vulnerability (CVSS 10.0) Under Active
Jan 25
Docker Security Fundamentals: Protecting Your Containers
Jan 25
Windows Security Baseline Audit: CIS Benchmark Compliance
Jan 24
Google Patches Actively Exploited Chrome Zero-Day
Jan 24
Windows Security Event Log Analysis: Detect Threats and
Jan 23
Nike Hit by Data Breach: 1.4 TB of Supply Chain Data Leaked
Jan 22
China-Linked Hackers Exploit VMware ESXi Zero-Days to
Jan 22
Pi-hole DNS Security: Block Ads, Trackers, and Malware
Jan 22
Build a Vulnerability Scanning Lab with OpenVAS
Jan 21
Mass Exploitation of Fortinet FortiGate Devices Underway
Jan 20
AI-Powered Phishing Achieves 54% Click-Through Rate
Jan 20
Implementing a Robust Backup Strategy: The 3-2-1 Rule
Jan 18
Supply Chain Attack Discovered in Popular NPM Packages
Jan 18
Critical D-Link Router RCE Under Active Exploitation - No
Jan 18
Build a Centralized Log Management System with Loki and
Jan 15
Covenant Health Ransomware Attack Impacts 478,000 Patients
Jan 15
Ivanti Connect Secure Under Active Attack - CISA Issues
Jan 15
Network Monitoring Basics: Detect Threats Before They Spread
Jan 14
Microsoft January 2026 Patch Tuesday: 114 Flaws Fixed, One
Jan 12
Telegram Investigating Claims of 30 Million User Data Breach
Jan 12
Build a Malware Analysis Sandbox with REMnux and FlareVM
Jan 10
Self-Hosting a Password Manager: Vaultwarden Setup Guide
Jan 8
US Treasury Department Confirms Network Breach by
Jan 6
Apple Releases Critical Security Updates Across All
Jan 5
Cybersecurity Predictions 2026: The Hype We Can Ignore and
Jan 5
Sedgwick Government Solutions Hit by TridentLocker