Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
Browse by Topic

All Tags

Explore our content organized by topic. Click on any tag to see related articles.

Popular Tags

#Vulnerability476 articles

• Android March 2026 Security Update Patches 129

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

View all
#CVE390 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

View all
#RCE310 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

View all
#Data Breach294 articles

• ShinyHunters Dumps 5.1 Million Panera Bread Customer

• Substack Discloses Data Breach After 100-Day Undetected

• Fintech Giant Figure Technology Confirms Breach: Nearly 1

View all
#Supply Chain268 articles

• WEF Global Cybersecurity Outlook 2026 Warns of 'Permanent

• Cline CLI Supply Chain Attack Installs Unauthorized

• Japanese Semiconductor Giant Advantest Hit by Ransomware

View all
#Ransomware228 articles

• ShinyHunters Dumps 5.1 Million Panera Bread Customer

• Ransomware in 2026: Data-Only Extortion Replaces Encryption

• HellCat Ransomware Group Breaches Ascom, Exfiltrates 44GB

View all
#Cybercrime214 articles

• WormGPT Hacked: 19,000 Cybercriminal AI Platform Users

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

View all
#Zero-Day192 articles

• Ex-L3Harris Executive Pleads Guilty to Selling Eight

• CrowdStrike 2026 Threat Report: eCrime Breakout Time Falls

• U.S. Treasury Sanctions Russian Zero-Day Broker Operation

View all
#Malware184 articles

• PromptSpy: First Android Malware to Weaponize Generative AI

• Google Disrupts Massive Chinese Espionage Campaign

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

View all
#NVD168 articles

• NIST to Stop Rating Non-Priority Flaws Due to Volume

• Federal Audit Reveals NIST's NVD Is Plagued by Poor Planning and Duplication

• CVE-2015-20118: Stored XSS in RealtyScript 4.0.2 Admin

View all
#BleepingComputer162 articles

• Telus Digital Confirms Massive Breach After ShinyHunters

• AppsFlyer Web SDK Supply Chain Attack Spread

• CISA Adds Wing FTP Server Flaw to KEV as RCE Chain Exploits

View all
#Threat Intelligence158 articles

• Ransomware in 2026: Data-Only Extortion Replaces Encryption

• AI-Driven Threats Accelerate: Agentic Attacks, Model

• AI-Armed Amateur Hacker Compromises 600+ FortiGate

View all
#Critical156 articles

• Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

• New FortiClient EMS Flaw Exploited in Attacks, Emergency

• New Critical Exim Mailer Flaw Allows Remote Code Execution

View all
#WordPress149 articles

• File Read Flaw in Smart Slider Plugin Impacts 500K

• Hackers Exploit Critical Flaw in Ninja Forms WordPress

• Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

View all
#AI Security145 articles

• AI-Driven Threats Accelerate: Agentic Attacks, Model

• WormGPT Hacked: 19,000 Cybercriminal AI Platform Users

• Cline CLI Supply Chain Attack Installs Unauthorized

View all
#Microsoft133 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Microsoft Releases Windows 11 OOB Hotpatch to Fix Three

• Windows 11 February Update Breaks C:\ Drive Access on Samsung PCs

View all
#SQL Injection119 articles

• Hackers Are Exploiting a Critical LiteLLM Pre-Auth SQLi Flaw

• Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

• Drupal: Critical SQL Injection Flaw Now Targeted in Attacks

View all
#Security Updates118 articles

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

View all
#The Hacker News107 articles

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

• GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison

• Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach

View all
#Privilege Escalation99 articles

• Cisco Patches Critical and High-Severity Vulnerabilities

• Disgruntled Researcher Leaks BlueHammer Windows Zero-Day

• GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables

View all
#Cloud Security93 articles

• Google's $32 Billion Wiz Acquisition Clears Final Hurdle as

• CrowdStrike 2026 Threat Report: eCrime Breakout Time Falls

• Cloudflare 2026 Threat Report: 230 Billion Daily Threats as

View all
#Windows91 articles

• Microsoft Releases Windows 11 OOB Hotpatch to Fix Three

• Microsoft Shares Fix for Windows C: Drive Access Issues on Samsung PCs

• Microsoft Halts Forced Global Rollout of Microsoft 365

View all
#Web Security89 articles

• AppsFlyer Web SDK Supply Chain Attack Spread

• Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

• Avada Builder WordPress Plugin Flaws Allow Site Credential

View all
#Authentication Bypass88 articles

• Cisco Patches Critical and High-Severity Vulnerabilities

• Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables

• Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now

View all
#Remote Code Execution82 articles

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

• Critical Langflow RCE Flaw Exploited Within 20 Hours of Disclosure

• CISA: New Langflow Flaw Actively Exploited to Hijack AI

View all
#Law Enforcement81 articles

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

View all
#APT76 articles

• Leaked Documents Reveal China's 'Expedition Cloud' Cyber

• Google Disrupts Massive Chinese Espionage Campaign

• Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

View all
#Security74 articles

• Apple Blocked Over $11 Billion in App Store Fraud in 6 Years

• Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention

• npm Adds 2FA-Gated Publishing and Package Install Controls

View all
#Russia68 articles

• Ex-L3Harris Executive Pleads Guilty to Selling Eight

• Pro-Russian Hacktivists Launch Sustained Cyber Campaign

• APT28 Operation MacroMaze: Russia-Linked Hackers Hit

View all
#Phishing67 articles

• Diesel Vortex: Russian Cybercrime Ring Steals 1,649

• Operation Epic Fury Triggers Unprecedented Cyber Escalation

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

View all
#PHP67 articles

• Microsoft Details Cookie-Controlled PHP Web Shells

• Laravel Lang Packages Hijacked to Deploy

• Laravel-Lang PHP Packages Compromised to Deliver

View all
#Nation-State64 articles

• Senator Demands AT&T, Verizon CEOs Testify Over Salt

• Operation Epic Fury Triggers Unprecedented Cyber Escalation

• Cloudflare 2026 Threat Report: 230 Billion Daily Threats as

View all
#AI64 articles

• Anthropic Exposes Industrial-Scale AI Distillation Attacks

• CrowdStrike 2026 Threat Report: eCrime Breakout Time Falls

• AI-Armed Amateur Hacker Compromises 600+ FortiGate

View all
#npm64 articles

• UNC6426 Weaponizes Old nx npm Compromise to Seize AWS Admin Access

• CanisterWorm: First Blockchain-Powered Self-Spreading Worm

• Attack on Axios Developer Tool Threatens Widespread

View all
#CISA KEV64 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• CISA Adds Wing FTP Server Flaw to KEV as RCE Chain Exploits

View all
#Healthcare63 articles

• Ransomware in 2026: Data-Only Extortion Replaces Encryption

• Ransomware Forces University of Mississippi Medical Center

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

View all
#Critical Infrastructure62 articles

• CISA Loses 62% of Workforce as DHS Shutdown Guts America's

• Japanese Semiconductor Giant Advantest Hit by Ransomware

• Ransomware Forces University of Mississippi Medical Center

View all
#Google57 articles

• Google's $32 Billion Wiz Acquisition Clears Final Hurdle as

• Google Disrupts Massive Chinese Espionage Campaign

• Android March 2026 Security Update Patches 129

View all
#Command Injection55 articles

• Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks

• CVE-2021-4473: Tianxin Behavior Management System

• CVE-2025-15379: MLflow Command Injection in Model Serving

View all
#Privacy53 articles

• Substack Discloses Data Breach After 100-Day Undetected

• IRS Shares Tax Data of 1.28 Million Individuals with DHS

• Persona Source Code Leak Exposes Hidden Biometric

View all
#CISA53 articles

• CISA Loses 62% of Workforce as DHS Shutdown Guts America's

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC

View all
#Open Source50 articles

• Cline CLI Supply Chain Attack Installs Unauthorized

• Betterleaks: New Open-Source Secrets Scanner Built to Replace Gitleaks

• Claude Code Source Code Accidentally Leaked in NPM Package

View all
#China49 articles

• Senator Demands AT&T, Verizon CEOs Testify Over Salt

• Anthropic Exposes Industrial-Scale AI Distillation Attacks

• Leaked Documents Reveal China's 'Expedition Cloud' Cyber

View all
#Unauthenticated49 articles

• WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

• Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

• CVE-2016-20052: Snews CMS 1.7 Unrestricted File Upload

View all
#Network Security48 articles

• Critical Unpatched GNU Telnetd Flaw (CVE-2026-32746)

• Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active

• Fortinet Warns of Critical RCE Flaws in FortiSandbox and FortiAuthenticator

View all
#Credential Theft47 articles

• Diesel Vortex: Russian Cybercrime Ring Steals 1,649

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

View all
#Linux47 articles

• Critical Unpatched GNU Telnetd Flaw (CVE-2026-32746)

• Microsoft Details Cookie-Controlled PHP Web Shells

• New 'Pack2TheRoot' Flaw Gives Hackers Root Linux Access

View all
#Social Engineering46 articles

• Scattered Lapsus$ ShinyHunters Alliance Hits 100+

• Fintech Giant Figure Technology Confirms Breach: Nearly 1

• Axios npm Hack Used Fake Teams Error Fix to Hijack

View all
#Espionage45 articles

• Ex-L3Harris Executive Pleads Guilty to Selling Eight

• APT28 Operation MacroMaze: Russia-Linked Hackers Hit

• Leaked Documents Reveal China's 'Expedition Cloud' Cyber

View all
#Cryptocurrency45 articles

• North Korea's UNC4899 Breached Crypto Firm via AirDropped

• AppsFlyer Web SDK Supply Chain Attack Spread

• Hacker Walks Away with $24.5 Million After Breaching Resolv

View all
#ShinyHunters42 articles

• ShinyHunters Dumps 5.1 Million Panera Bread Customer

• Scattered Lapsus$ ShinyHunters Alliance Hits 100+

• Fintech Giant Figure Technology Confirms Breach: Nearly 1

View all
#Patch Tuesday42 articles

• Android March 2026 Security Update Patches 129

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

• Microsoft Releases Windows 11 OOB Hotpatch to Fix Three

View all
#Active Exploitation40 articles

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active

• CISA: New Langflow Flaw Actively Exploited to Hijack AI

View all
#GitHub39 articles

• UNC6426 Weaponizes Old nx npm Compromise to Seize AWS Admin Access

• GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison

• The State of Secrets Sprawl 2026: 9 Takeaways for CISOs

View all
#sentinelone39 articles

• The Good, the Bad and the Ugly in Cybersecurity – Week 14

• Hypersonic Supply Chain Attacks: AI Defense Stops Zero-Days

• Researchers Uncover Pre-Stuxnet 'fast16' Malware Targeting

View all
#Path Traversal39 articles

• Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks

• 7 Unpatched Flaws Disclosed in FatFs Filesystem Used in Millions of Embedded Devices

• Progress Confirms ShareFile Zero-Day Flaw Behind Storage Zone Shutdown

View all
#automation39 articles

• How to Configure Microsoft Sentinel Analytics Rules

• Automating Report Generation with Python and Jinja2

• Automated News Aggregation with Deduplication Algorithms

View all
#Cisco38 articles

• Interlock Ransomware Has Been Exploiting Cisco FMC Zero-Day

• CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC

• Interlock Ransomware Exploited Cisco FMC Zero-Day for 36

View all
#Account Takeover38 articles

• Device Code Phishing Attacks Surge 37x as New Kits Spread

• Why Chargebacks Are Just One Piece of the Fraud Puzzle

• Hackers Used Meta's AI Support Bot to Seize Instagram Accounts

View all
#edr38 articles

• Trellix Source Code Breach Highlights Growing Supply Chain

• Gentlemen Ransomware Uses Multiple EDR Killers to Disable Defenses

• GodDamn Ransomware Deploys Microsoft-Signed PoisonX Driver to Kill EDR Tools

View all
#Plugin Vulnerability38 articles

• WP Maps Pro Bug Exploited to Create Admin Accounts on WordPress Sites

• CVE-2016-20066: WordPress CP Polls Persistent XSS via File Upload

• CVE-2026-12761: miniOrange WordPress Social Login Auth Bypass Enables Full Admin Takeover

View all
#File Upload37 articles

• Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

• CVE-2015-20115: RealtyScript 4.0.2 Stored XSS via File

• CVE-2016-20052: Snews CMS 1.7 Unrestricted File Upload

View all
#IoT36 articles

• DoJ Disrupts 3 Million-Device IoT Botnets Behind Record

• Weekly Recap: CI/CD Backdoor, FBI Buys Location Data

• Feds Disrupt IoT Botnets Behind Huge DDoS Attacks

View all
#Fortinet34 articles

• AI-Armed Amateur Hacker Compromises 600+ FortiGate

• Critical Fortinet FortiClient EMS Flaw Now Exploited in Attacks

• Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

View all
#Infostealer34 articles

• VoidStealer Malware Steals Chrome Master Key via Debugger

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• Trivy Supply Chain Attack Targets CI/CD Secrets

View all
#Router34 articles

• Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

• Cisco IOS XE Web UI Privilege Escalation Actively Exploited

• CVE-2024-51311: Critical Stack Overflow in Tenda TX9 Router Firmware

View all
#Government33 articles

• IRS Shares Tax Data of 1.28 Million Individuals with DHS

• LexisNexis Confirms Cloud Breach Exposing 400K User

• European Commission Confirms Data Breach After Europa.eu

View all
#policy33 articles

• CISA Loses 62% of Workforce as DHS Shutdown Guts America's

• Here's How the FTC Plans to Enforce the Take It Down Act

• Can Laws Stop Deepfakes? South Korea Aims to Find Out

View all
#Fraud33 articles

• Adversaries Exploit Vacant Homes to Intercept Mail in Hybrid Cybercrime

• FCC Proposes $4.5 Million Fine for Voice Provider Hosting

• Over 20,000 Crypto Fraud Victims Identified in International Crackdown

View all
#SourceCodester33 articles

• CVE-2025-69941: Critical SQL Injection in Tailor Management System — Measurement Endpoint

• CVE-2025-69947: Critical SQL Injection in Tailor Management System — Customer Edit Endpoint

• CVE-2026-10184: SourceCodester Hospital Records SQL Injection via Delete

View all
#Android32 articles

• PromptSpy: First Android Malware to Weaponize Generative AI

• Android March 2026 Security Update Patches 129

• Android 17 Blocks Non-Accessibility Apps from Accessibility

View all
#North Korea31 articles

• North Korea's UNC4899 Breached Crypto Firm via AirDropped

• Axios NPM Package Breached in North Korean Supply Chain

• Google Attributes Axios npm Supply Chain Attack to North

View all
#DevSecOps31 articles

• Betterleaks: New Open-Source Secrets Scanner Built to Replace Gitleaks

• The State of Secrets Sprawl 2026: 9 Takeaways for CISOs

• Cisco Source Code Stolen in Trivy-Linked Dev Environment

View all
#Docker31 articles

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• Malicious KICS Docker Images and VS Code Extensions Hit

• Open Source DockSec Uses AI to Cut Through Vulnerability

View all
#CWE-8931 articles

• CVE-2019-25662: ResourceSpace 8.6 Unauthenticated SQL

• Critical Blind SQL Injection in Akilli E-Commerce Website

• CVE-2025-62319: Critical SQL Injection in HCL Unica (CVSS

View all
#OpenAI30 articles

• Persona Source Code Leak Exposes Hidden Biometric

• OpenAI Says ChatGPT Ads Are Not Rolling Out Globally For Now

• ChatGPT Rolls Out New $100 Pro Subscription to Challenge

View all
#AWS30 articles

• LexisNexis Confirms Cloud Breach Exposing 400K User

• UNC6426 Weaponizes Old nx npm Compromise to Seize AWS Admin Access

• AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable

View all
#Botnet30 articles

• DoJ Disrupts 3 Million-Device IoT Botnets Behind Record

• Manager of Botnet Used in Ransomware Attacks Gets 2 Years

• Feds Disrupt IoT Botnets Behind Huge DDoS Attacks

View all
#Deserialization30 articles

• PTC Warns of Imminent Threat from Critical Windchill

• Critical Flaw in protobuf.js Library Enables JavaScript

• Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

View all
#Anthropic29 articles

• Anthropic Exposes Industrial-Scale AI Distillation Attacks

• Claude Code Source Code Accidentally Leaked in NPM Package

• Claude Code Source Leaked via npm Packaging Error

View all
#threat-hunting29 articles

• Velociraptor DFIR Setup, Hunts, and Forensic Collection

• Osquery Endpoint Visibility & Threat Hunting

• Linux auditd: Kernel-Level Security Monitoring and Compliance Logging

View all
#Incident Response28 articles

• Stryker Cyberattack Wiped Tens of Thousands of Devices — No

• Dutch Finance Ministry Takes Treasury Banking Portal

• The Backup Myth That Is Putting Businesses at Risk

View all
#TeamPCP28 articles

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• Trivy Supply Chain Attack Targets CI/CD Secrets

• TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides

View all
#Apple27 articles

• CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog

• Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple

• Apple Expands iOS 18 Updates to More iPhones to Block

View all
#Chrome27 articles

• VoidStealer Malware Steals Chrome Master Key via Debugger

• Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in 2026

• New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation

View all
#firewall27 articles

• Firestarter Malware Survives Cisco Firewall Updates and Security Patches

• FIRESTARTER Backdoor Hit Federal Cisco Firepower Device

• FortiBleed: Russian IAB Harvested 110 Million Credentials from 430,000 FortiGate Firewalls

View all
#ICS27 articles

• ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days

• Accenture to Acquire Majority Stake in Dragos, runZero, and NetRise in $4.1 Billion OT Cybersecurity Push

• Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack

View all
#VPN27 articles

• Hackers Bypass SonicWall VPN MFA Due to Incomplete Patching

• Europe Dismantles VPN Service Used by Cybercriminals to Hide Ransomware Attacks

• Police Seize 'First VPN' Service Used in Ransomware and Data Theft Attacks

View all
#deployment27 articles

• SentinelOne Application Control Policies

• SentinelOne Control vs Complete Feature Comparison

• SentinelOne Create and Manage Exclusion Policies

View all
#detection-rules27 articles

• SentinelOne Application Control Policies

• SentinelOne Control vs Complete Feature Comparison

• SentinelOne Create and Manage Exclusion Policies

View all
#Agentic AI26 articles

• AI-Driven Threats Accelerate: Agentic Attacks, Model

• OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click

• Shadow AI in SaaS: How Hidden AI Agents Are Enabling

View all
#Developer Security26 articles

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

• GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison

• Attack on Axios Developer Tool Threatens Widespread

View all
#Python26 articles

• GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison

• Supply Chain Attack Hits Widely-Used AI Package, Risking

• Backdoored Telnyx PyPI Package Pushes Malware Hidden in WAV

View all
#XSS26 articles

• Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks

• Microsoft Exchange Zero-Day Under Attack, No Patch Available

• Zimbra Urges Customers to Patch Critical Web Client XSS Flaw Exploited in the Wild

View all
#api26 articles

• OpenAI Temporarily Relaxes GPT-5.6 Sol Usage Limits Amid Demand Surge

• FortiGate Firewall Policy Management with PowerShell

• SentinelOne Application Control Policies

View all
#Extortion25 articles

• Former DigitalMint Ransomware Negotiator Pleads Guilty to $75.3M Extortion Scheme

• ADT Confirms Data Breach After ShinyHunters Leak Threat

• New BlackFile Extortion Group Linked to Surge of Vishing

View all
#Web Application25 articles

• Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites

• Apache Struts Critical RCE via OGNL Injection Returns

• CVE-2018-25362: Twitter-Clone SQL Injection via follow.php

View all
#Mobile Security24 articles

• PromptSpy: First Android Malware to Weaponize Generative AI

• Android March 2026 Security Update Patches 129

• Android 17 Blocks Non-Accessibility Apps from Accessibility

View all
#Authorization Bypass24 articles

• Coolify CVE-2026-34047: Terminal WebSocket Authorization Bypass (CVSS 9.9)

• CVE-2026-11807: Critical Authorization Bypass in Event-Driven Ansible WebSocket API

• CVE-2026-12153: WP Learn Manager Plugin — Unauthenticated Authorization Bypass Allows Plugin Installation

View all
#FBI23 articles

• FBI Warns of ATM Jackpotting Surge as Losses Top $20

• Ransomware Forces University of Mississippi Medical Center

• FBI Warns Russian Intelligence Targeting Signal and WhatsApp in Mass Phishing Campaign

View all
#macOS23 articles

• Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

• New Infinity Stealer Malware Grabs macOS Data via ClickFix

• In Other News: ChatGPT Data Leak, Android Rootkit, Water

View all
#CVSS 9.823 articles

• CVE-2026-10042: manga-image-translator RCE via Unsafe Python Deserialization

• CVE-2026-11849: IRM-IEI Remote Management Hardcoded Credentials

• CVE-2026-14894: WordPress Super Forms Plugin Critical Arbitrary File Upload

View all
#DOJ22 articles

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

• DoJ Disrupts 3 Million-Device IoT Botnets Behind Record

View all
#ClickFix22 articles

• Termite Ransomware Operator Velvet Tempest Chains ClickFix

• LeakNet Ransomware Weaponizes ClickFix and Deno Runtime for Stealthy Corporate Attacks

• Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

View all
#SecurityWeek22 articles

• Navia Data Breach Impacts 2.7 Million People

• Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

• Cisco Patches Critical and High-Severity Vulnerabilities

View all
#Azure22 articles

• Microsoft Patch Tuesday, March 2026 Edition

• ConsentFix v3 Automates Azure OAuth Abuse With Mass

• Microsoft Rejects Critical Azure Vulnerability Report, No

View all
#Buffer Overflow22 articles

• Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches

• CVE-2016-20049: JAD Java Decompiler Stack-Based Buffer

• CVE-2017-20225: TiEmu TI Calculator Emulator Stack Buffer

View all
#incident-response22 articles

• Network Traffic Analysis with Zeek: From Deployment to Threat Detection

• Velociraptor DFIR Setup, Hunts, and Forensic Collection

• SentinelOne Application Control Policies

View all
#Enterprise Security21 articles

• Google: 90 Zero-Days Exploited in 2025 — Enterprise Tech

• New Progress ShareFile Flaws Can Be Chained in Pre-Auth RCE

• Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively

View all
#Ukraine21 articles

• Spanish-Ukrainian Police Bust Gambling Ring That Exploited

• Pro-Ukraine Hacker Group Bearlyfy Targets Russian Companies

• Bearlyfy Hits Russian Firms with Custom GenieLocker

View all
#Browser Security21 articles

• Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in 2026

• New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation

• Microsoft Backpedals: Edge to Stop Loading Cleartext

View all
#CI/CD20 articles

• UNC6426 Weaponizes Old nx npm Compromise to Seize AWS Admin Access

• Trivy Security Scanner GitHub Actions Breached — 75 Tags

• Trivy Supply Chain Attack Targets CI/CD Secrets

View all
#KEV20 articles

• CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• CISA: New Langflow Flaw Actively Exploited to Hijack AI

View all
#WooCommerce19 articles

• Funnel Builder WordPress Plugin Bug Exploited to Steal

• Funnel Builder Flaw Under Active Exploitation Enables

• CVE-2025-10656: WooCommerce Plugin Missing Authorization Allows Unauthenticated Admin Account Creation

View all
#Homelab19 articles

• Building a Secure Homelab in 2026: Complete Guide

• Keycloak SSO: Self-Hosted Identity Provider for Your Homelab

• Build a Collaborative IPS with CrowdSec

View all
#E-Commerce18 articles

• PolyShell Attacks Target 56% of All Vulnerable Magento

• WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

• Hackers Use Pixel-Large SVG Trick to Hide Credit Card

View all
#IoT Security18 articles

• ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache

• Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack

• EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

View all
#Code Injection18 articles

• Actively Exploited Apache ActiveMQ Flaw Impacts 6,400

• CVE-2025-32432: Craft CMS Code Injection Vulnerability

• CVE-2025-54068: Laravel Livewire Code Injection

View all
#OS Command Injection18 articles

• CVE-2026-10520: Ivanti Sentry OS Command Injection — CVSS 10.0

• CVE-2026-15511: Critical OS Command Injection in Comfast CF-WR631AX Router

• CVE-2026-27130 — Dokploy OS Command Injection via appName

View all
#Cybersecurity17 articles

• WEF Global Cybersecurity Outlook 2026 Warns of 'Permanent

• Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

• Trellix Confirms Source Code Breach With Unauthorized

View all
#Sandbox Escape17 articles

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

• Edgecution: Malicious Edge Extension Escapes Browser Sandbox via Native Messaging

• n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

View all
#Prompt Injection17 articles

• OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click

• Microsoft, Salesforce Patch AI Agent Data Leak Flaws

• New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

View all
#Oracle17 articles

• Oracle Pushes Emergency Fix for Critical Identity Manager

• Oracle Mitigates PeopleSoft Zero-Day Exploited in Data Theft Attacks

• ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities

View all
#Kubernetes17 articles

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• VoidLink: AI-Generated Cloud-Native Malware Framework

• CVE-2025-69902: Critical Command Injection in kubectl-mcp-server

View all
#Compliance17 articles

• Healthcare Software Firm CareCloud Informs SEC of Potential

• DORA and Operational Resilience: Credential Management as a

• New Initiative Tackles Security for End-of-Life Open Source Software

View all
#SSRF17 articles

• LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

• CVE-2026-20230: Cisco Unified CM WebDialer SSRF Now Exploited in the Wild

• CVE-2025-12886: Oxygen Theme SSRF Allows Unauthenticated

View all
#OT Security17 articles

• EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

• Exposed Fuel Tank Gauges Under Attack in the US

• Australian Sugar Producer Works to Restore Operations After Ransomware Attack

View all
#SIEM17 articles

• Only 10% of SOCs Say They're Getting Excellent Value From AI — What the Second Wave Must Deliver

• Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

• CVE-2026-17561: Critical Code Injection in Logsign SIEM

View all
#Telecom16 articles

• Senator Demands AT&T, Verizon CEOs Testify Over Salt

• Ericsson US Discloses Data Breach Affecting Employees and Customers

• Telus Digital Confirms Massive Breach After ShinyHunters

View all
#DDoS16 articles

• Pro-Russian Hacktivists Launch Sustained Cyber Campaign

• Iran Plunged Into Digital Darkness: Internet Drops to 4% in Cyberattack

• Cloudflare 2026 Threat Report: 230 Billion Daily Threats as

View all
#Iran16 articles

• Iran Plunged Into Digital Darkness: Internet Drops to 4% in Cyberattack

• Operation Epic Fury Triggers Unprecedented Cyber Escalation

• Iran-Linked Hackers Breach FBI Director's Personal Email

View all
#Takedown16 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3

• Police Seize 'First VPN' Service Used in Ransomware and Data Theft Attacks

View all
#Identity Security16 articles

• Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks

• Why Simple Breach Monitoring Is No Longer Enough

• Your Next Breach Will Look Like Business as Usual

View all
#Email Security16 articles

• Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks

• New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

• Microsoft Warns of Exchange Zero-Day Flaw Exploited in Attacks

View all
#CVSS 1016 articles

• Ubiquiti Patches Three Max-Severity UniFi OS Vulnerabilities

• Metabase SQLi Zero-Day Exploited in Customer Data-Theft Attacks

• CVE-2017-20230: Perl Storable Stack Overflow — CVSS 10.0

View all
#Java16 articles

• Fastjson 1.x RCE Actively Exploited With No Patch Available

• Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patch Available

• Hackers Target US Firms in FastJson RCE Zero-Day Attacks

View all
#forensics16 articles

• New Tool Traces AI-Generated Videos Back to Their Source

• Velociraptor DFIR Setup, Hunts, and Forensic Collection

• SentinelOne Control vs Complete Feature Comparison

View all
#Perl16 articles

• CVE-2009-10007: Catalyst::Plugin::Authentication Session Fixation

• CVE-2011-10043: Perl Module::Load Arbitrary Module Injection Resurfaces

• CVE-2017-20230: Perl Storable Stack Overflow — CVSS 10.0

View all
#Funding15 articles

• Cloud Security Startup Native Exits Stealth With $42

• Eclypsium Raises $25 Million to Expand Device Supply Chain

• Exaforce Raises $125 Million for Agentic SOC Platform

View all
#OAuth15 articles

• Shadow AI in SaaS: How Hidden AI Agents Are Enabling

• Device Code Phishing Attacks Surge 37x as New Kits Spread

• Vercel Employee's AI Tool Access Led to Data Breach

View all
#GitHub Actions15 articles

• Trivy Security Scanner GitHub Actions Breached — 75 Tags

• Trivy Vulnerability Scanner Breached to Push Infostealer

• Trivy Supply Chain Attack Targets CI/CD Secrets

View all
#PyPI15 articles

• Supply Chain Attack Hits Widely-Used AI Package, Risking

• Backdoored Telnyx PyPI Package Pushes Malware Hidden in WAV

• TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides

View all
#Patch Now15 articles

• Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks

• Critical Fortinet FortiClient EMS Flaw Now Exploited in Attacks

• Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE

View all
#Claude15 articles

• Claude Code Source Leaked via npm Packaging Error

• Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws

• Can Anthropic Keep Its Exploit-Writing AI Out of the Wrong

View all
#D-Link15 articles

• New Mirai Campaign Exploits RCE Flaw in End-of-Life D-Link

• CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal

• AryStinger Botnet Infected Thousands of D-Link Routers Worldwide

View all
#Education14 articles

• ShinyHunters Dumps Harvard and UPenn Data After Ransom

• ShinyHunters Breach Infinite Campus — K-12 Platform Serving

• Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

View all
#Europol14 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Spanish-Ukrainian Police Bust Gambling Ring That Exploited

• Operation Synergia III: Police Sinkhole 45,000 IPs in Global Cybercrime Crackdown

View all
#Third-Party Risk14 articles

• Ericsson US Discloses Data Breach Affecting Employees and Customers

• Marquis Ransomware Breach: 672K People Exposed as Attack

• Hims & Hers Warns of Data Breach After Zendesk Support

View all
#Salesforce14 articles

• ShinyHunters Claims Mass Data Theft From 400 Firms via Salesforce Aura

• Microsoft, Salesforce Patch AI Agent Data Leak Flaws

• 7-Eleven Data Breach Confirmed After ShinyHunters Ransom

View all
#Firmware14 articles

• Eclypsium Raises $25 Million to Expand Device Supply Chain

• Flipper Zero Firmware Development Continues With Community Help

• Six U-Boot Flaws Could Enable Stealthy Firmware Attacks on Embedded Devices

View all
#Patch14 articles

• Oracle Pushes Emergency Fix for Critical Identity Manager

• Hackers Now Exploit Critical F5 BIG-IP Flaw in Attacks

• Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

View all
#iOS14 articles

• CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog

• DarkSword GitHub Leak Threatens to Turn Elite iPhone

• TA446 Deploys DarkSword iOS Exploit Kit in Targeted

View all
#DeFi14 articles

• Hacker Walks Away with $24.5 Million After Breaching Resolv

• Hacker Charged with Stealing $53 Million from Uranium

• Crypto Platform Drift Suspends Services After Hundreds of Millions Stolen

View all
#Backdoor14 articles

• Axios NPM Package Breached in North Korean Supply Chain

• China-Linked APT GopherWhisper Abuses Legitimate Services

• CryptoBandits Malware Doubles as a Backdoor, Abuses Tor for Stealthy C2

View all
#Adobe14 articles

• Adobe Reader Zero-Day Exploited via Malicious PDFs Since

• Hackers Exploiting Acrobat Reader Zero-Day Flaw Since

• Adobe Patches Actively Exploited Zero-Day That Lingered for Months

View all
#Endpoint Security14 articles

• Payouts King Ransomware Uses QEMU Virtual Machines to Bypass Endpoint Security

• Microsoft Warns of New Defender Zero-Days Exploited in Attacks

• Trend Micro Warns of Apex One Zero-Day Exploited in the Wild

View all
#MCP14 articles

• Anthropic MCP Design Vulnerability Enables RCE, Threatening

• 2-Click Cursor Exploit Enables Dev Environment Takeover

• Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

View all
#SD-WAN14 articles

• Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited

• Cisco Catalyst SD-WAN Controller Auth Bypass Actively

• Cisco Warns of Unpatched SD-WAN Zero-Day Exploited in Attacks

View all
#PowerShell14 articles

• ClickFix Attacks Evolve to Abuse DNS nslookup for Payload Delivery

• How to Detect and Block ClickFix Attacks

• Windows Server Hardening: A Complete Security Guide for Enterprises

View all
#API Security14 articles

• CVE-2025-71327: Flowise Authentication Bypass Grants Full API Access

• CVE-2026-14450: MaaS API Auth Bypass via Forged HTTP Headers

• CVE-2026-25197: IDOR Flaw Lets Authenticated Users Access

View all
#Insider Threat13 articles

• Ex-L3Harris Executive Pleads Guilty to Selling Eight

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

• New Jersey Men Sentenced to Combined 17 Years for Running

View all
#FortiGate13 articles

• AI-Armed Amateur Hacker Compromises 600+ FortiGate

• FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices

• FortiBleed Campaign Used Custom FortiGate Sniffer to Steal Credentials

View all
#JavaScript13 articles

• AppsFlyer Web SDK Supply Chain Attack Spread

• Critical Flaw in protobuf.js Library Enables JavaScript

• New npm Supply Chain Attack Self-Spreads to Steal Developer

View all
#Langflow13 articles

• CISA: New Langflow Flaw Actively Exploited to Hijack AI

• Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks

• Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

View all
#Netherlands13 articles

• Dutch Finance Ministry Takes Treasury Banking Portal

• Healthcare IT Provider ChipSoft Hit by Ransomware Attack

• Dutch Hospitals Disrupted After Ransomware Hits Healthcare

View all
#Microsoft 36513 articles

• Device Code Phishing Attacks Surge 37x as New Kits Spread

• ConsentFix v3 Automates Azure OAuth Abuse With Mass

• Tycoon2FA Hijacks Microsoft 365 Accounts via Device-Code

View all
#Security Research13 articles

• Black Hat USA 2026: What to Expect from the Year''s Biggest

• 1 Billion CISA KEV Records Reveal Human-Scale Security Has

• Analysis of 216M Security Findings Shows a 4x Increase in Critical Risk (2026 Report)

View all
#Artificial Intelligence13 articles

• Commerce Setting Up New AI Export Regime to Push Adoption

• Google Detects First AI-Generated Zero-Day Exploit in the Wild

• Google: Hackers Used AI to Develop Zero-Day Exploit for Web

View all
#Zero Trust13 articles

• Your Next Breach Will Look Like Business as Usual

• Cybersecurity Evolution: From Perimeter Defense to AI-Native Security

• Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense

View all
#SonicWall13 articles

• ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force

• Hackers Bypass SonicWall VPN MFA Due to Incomplete Patching

• SonicWall Warns of SMA1000 Flaws Exploited in Zero-Day Attacks, Patch Now

View all
#VMware13 articles

• Kyber Ransomware Gang Uses Post-Quantum Encryption to Target Windows and ESXi

• Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL

• Hackers Earn $1,298,250 for 47 Zero-Days at Pwn2Own Berlin

View all
#cPanel13 articles

• cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug

• Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now

• Critical cPanel Flaw Mass-Exploited in 'Sorry' Ransomware

View all
#DNS13 articles

• Microsoft Patches 138 Vulnerabilities Including DNS and Netlogon RCE Flaws

• 'Underminr' Vulnerability Lets Attackers Hide Malicious

• Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

View all
#CMS13 articles

• Drupal Patches Highly Critical Vulnerability Exposing

• CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

• Australia Warns of Global Campaign Targeting Vulnerable CMS Platforms

View all
#Node.js13 articles

• Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

• NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

• Amazon Links Debug, Chalk NPM Supply Chain Attacks to North Korean Hackers

View all
#Access Control13 articles

• FIFA Bug Exposes World Cup Streams to Remote Takeover

• Forget Data Leakage: Shadow AI's Real Threat Is Access Control

• CVE-2018-25391: HaPe PKH 1.1 Unauthenticated Record Deletion via Missing Authorization

View all
#CWE-7813 articles

• CVE-2021-4473: Tianxin Behavior Management System

• CVE-2026-0596: MLflow Command Injection via Unsanitized

• CVE-2026-12486: GeoVision GV-I/O Box 4E OS Command Injection via libNetSetObj.so

View all
#mitre-attack13 articles

• SentinelOne Control vs Complete Feature Comparison

• SentinelOne Deep Visibility Threat Hunting

• SentinelOne File Fetch and Forensic File Collection

View all
#PII12 articles

• Japan Airlines Confirms Data Breach Affecting 28,000

• IDMerit KYC Data Breach Exposes 1 Billion Records Across 26

• Ericsson US Discloses Data Breach Affecting Employees and Customers

View all
#Blockchain12 articles

• CanisterWorm: First Blockchain-Powered Self-Spreading Worm

• Hacker Walks Away with $24.5 Million After Breaching Resolv

• Google Slashes Quantum Resource Requirements for Breaking

View all
#General12 articles

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• Weekly Recap: CI/CD Backdoor, FBI Buys Location Data

• Anti-Piracy Coalition Takes Down AnimePlay App with 5

View all
#Cryptography12 articles

• Google Slashes Quantum Resource Requirements for Breaking

• Apple Open-Sources Quantum-Resistant Encryption Code

• Security Roundup: OpenAI Open Sources Codex Security CLI, AWS Pins NPM Attacks on North Korea, Anthropic Mythos Cracks Crypto

View all
#Open Source Security12 articles

• The State of Trusted Open Source Report: Key Findings for 2025

• Axios npm Hack Used Fake Teams Error Fix to Hijack

• 13-Year-Old Bug in ActiveMQ Lets Hackers Remotely Execute

View all
#NGINX12 articles

• Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables

• 18-Year-Old NGINX Rewrite Module Flaw Enables

• 18-Year-Old NGINX Vulnerability Allows DoS and Potential RCE

View all
#Active Directory12 articles

• Why Changing Passwords Doesn't End an Active Directory

• Microsoft: Domain Controller Lookup May Fail on Windows

• Can You Enforce Strong Active Directory Password Rules Without Frustrating Users?

View all
#TLS12 articles

• HollowByte: 11-Byte Payload Triggers Memory Bloat DoS on OpenSSL Servers

• Google Begins Post-Quantum Cryptography Rollout Across

• CVE-2026-35560: Amazon Athena ODBC Driver Fails Certificate

View all
#Totolink12 articles

• CVE-2026-10187: Totolink N300RH Stack Buffer Overflow in WiFi Config

• CVE-2026-31027: TOTOlink A3600R Buffer Overflow in setAppEasyWizardConfig

• CVE-2026-36841: TOTOLINK N200RE V5 Command Injection

View all
#Dark Web11 articles

• WormGPT Hacked: 19,000 Cybercriminal AI Platform Users

• AT&T Breach Data Resurfaces: 176 Million Records with Fully

• Paid AI Accounts Are Now a Hot Underground Commodity

View all
#Enterprise11 articles

• HellCat Ransomware Group Breaches Ascom, Exfiltrates 44GB

• Microsoft Shares Fix for Windows C: Drive Access Issues on Samsung PCs

• Microsoft Halts Forced Global Rollout of Microsoft 365

View all
#Japan11 articles

• Japanese Semiconductor Giant Advantest Hit by Ransomware

• Mazda Discloses Security Breach Exposing Employee and Partner Data

• Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

View all
#Identity Theft11 articles

• AT&T Breach Data Resurfaces: 176 Million Records with Fully

• IDMerit KYC Data Breach Exposes 1 Billion Records Across 26

• Ericsson US Discloses Data Breach Affecting Employees and Customers

View all
#RaaS11 articles

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

• Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak

• Who Runs the Ransomware Group 'The Gentlemen'?

View all
#HIPAA11 articles

• Cognizant TriZetto Breach Exposes Health Data of 3.4

• 3.1 Million Impacted by QualDerm Partners Data Breach

• 250,000 Affected by Data Breach at Nacogdoches Memorial

View all
#ChatGPT11 articles

• OpenAI Says ChatGPT Ads Are Not Rolling Out Globally For Now

• In Other News: ChatGPT Data Leak, Android Rootkit, Water

• ChatGPT Rolls Out New $100 Pro Subscription to Challenge

View all
#Weekly Recap11 articles

• Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach

• Weekly Recap: CI/CD Backdoor, FBI Buys Location Data

• Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple

View all
#Startup11 articles

• Cloud Security Startup Native Exits Stealth With $42

• Eclypsium Raises $25 Million to Expand Device Supply Chain

• Socket Raises $60 Million at $1 Billion Valuation

View all
#Worm11 articles

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• Mini Shai-Hulud Worm Compromises TanStack, Mistral AI

• Worm Redux: Fresh Mini Shai-Hulud Infections Bite npm

View all
#The Record11 articles

• Supply Chain Attack Hits Widely-Used AI Package, Risking

• Dutch Court Threatens xAI with Fines Over Grok's

• European Parliament Rejects Extension of CSAM Scanning

View all
#smb11 articles

• 6-Year Ransomware Campaign Targets Turkish Homes and SMBs

• CVE-2026-4149: Sonos Era 300 Unauthenticated RCE via SMB

• Why Every Business Needs Cyber Insurance in 2026

View all
#authentication11 articles

• cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug

• Chinese Hackers Hijack Auth Flow, Spy on Isolated Network for a Decade

• CVE-2025-57735: Apache Airflow JWT Token Not Invalidated on Logout

View all
#SOC11 articles

• In Other News: Scattered Spider Member Arrested, SOC

• One Missed Threat Per Week: What 25M Alerts Reveal About

• Exaforce Raises $125 Million for Agentic SOC Platform

View all
#UK11 articles

• UK Water Utility Fined £963,900 After Cl0p Lurked

• UK Fines Water Supplier $1.3M for Exposing Data of 664K

• GCHQ Chief: AI Is an 'Unstoppable Force' with Offensive and Defensive Cyber Ramifications

View all
#Memory Corruption11 articles

• New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

• Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

• CVE-2025-43510: Apple Multiple Products Improper Locking

View all
#Ubiquiti11 articles

• Ubiquiti Patches Three Max-Severity UniFi OS Vulnerabilities

• UniFi OS Command Injection via Improper Input Validation

• UniFi OS Improper Access Control — Unauthorized System

View all
#Joomla11 articles

• CISA Orders Feds to Patch Max Severity Joomla Plugin Flaw by Friday

• CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

• CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions

View all
#High11 articles

• CVE-2025-2749: Kentico Xperience Path Traversal

• CVE-2025-43510: Apple Multiple Products Improper Locking

• CVE-2026-10167: School Student Management System Cookie Auth Bypass

View all
#Hardening11 articles

• Lynis: Linux Security Auditing and Hardening in Practice

• Nginx + ModSecurity WAF: Protecting Web Apps with OWASP CRS

• Domain Controller Hardening: Securing Active Directory

View all
#Actively Exploited10 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• Recent Apache ActiveMQ Vulnerability Exploited in the Wild

• Adobe Patches Actively Exploited Zero-Day That Lingered for Months

View all
#LLM10 articles

• Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple

• Claude Fable 5 Isn't Permanently Leaving Subscriptions, Anthropic Says

• Claude Fable Relaunch Disappoints Users With Nerfed Performance

View all
#RAT10 articles

• Attack on Axios Developer Tool Threatens Widespread

• Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

• CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

View all
#Use-After-Free10 articles

• Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in 2026

• New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation

• Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

View all
#Container Security10 articles

• The State of Trusted Open Source Report: Key Findings for 2025

• Chainguard Unveils Factory 2.0 to Automate Hardening the Software Supply Chain

• Open Source DockSec Uses AI to Cut Through Vulnerability

View all
#SAP10 articles

• SAP-Related npm Packages Compromised in Credential-Stealing

• TeamPCP Hits SAP npm Packages With 'Mini Shai-Hulud' Supply

• 1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, and Intercom

View all
#Ivanti10 articles

• CISA Gives Federal Agencies Four Days to Patch Actively

• Ivanti Customers Confront Yet Another Actively Exploited

• Ivanti Warns of New EPMM Flaw Exploited in Zero-Day Attacks

View all
#TanStack10 articles

• Mini Shai-Hulud Worm Compromises TanStack, Mistral AI

• Worm Redux: Fresh Mini Shai-Hulud Infections Bite npm

• OpenAI Asks macOS Users to Update After TanStack npm Supply

View all
#Manufacturing10 articles

• West Pharmaceutical Services Hit by Disruptive Ransomware

• West Pharmaceutical Warns of Ransomware Attack Impacting

• Foxconn Confirms Cyberattack Claimed by Nitrogen Ransomware

View all
#UniFi10 articles

• Ubiquiti Patches Three Max-Severity UniFi OS Vulnerabilities

• Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

• CVE-2026-34909 — UniFi OS Path Traversal Leading to Account

View all
#IBM10 articles

• IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under "Project Lightwell"

• Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.

• CVE-2025-36359: IBM DevOps Session Hijacking Vulnerability (CVSS 8.1)

View all
#Stored XSS10 articles

• CVE-2015-20115: RealtyScript 4.0.2 Stored XSS via File

• CVE-2026-10081: Unlimited Elements for Elementor Stored XSS via Google Reviews

• CVE-2026-2342: ValeApp Stored Cross-Site Scripting (CVSS 9.3)

View all
#Database10 articles

• CVE-2018-25362: Twitter-Clone SQL Injection via follow.php

• CVE-2024-46636: NASA EOSDIS MODAPS v8.1 SQL Injection

• CVE-2026-11334: SQL Injection in College Management System

View all
#Plugin10 articles

• CVE-2025-12886: Oxygen Theme SSRF Allows Unauthenticated

• CVE-2026-13439: WordPress Easy Form Builder Unauthenticated Privilege Escalation (CVSS 9.8)

• CVE-2026-14545: TrueBooker WordPress Plugin Lets Anyone Take Over Admin Accounts

View all
#OpenClaw9 articles

• Cline CLI Supply Chain Attack Installs Unauthorized

• OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click

• More Malicious OpenClaw Skills Threaten AI Supply Chain

View all
#Vulnerability Research9 articles

• Google: 90 Zero-Days Exploited in 2025 — Enterprise Tech

• Black Hat USA 2026: What to Expect from the Year''s Biggest

• GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables

View all
#Money Laundering9 articles

• Spanish-Ukrainian Police Bust Gambling Ring That Exploited

• US Sentences Nigerian National to 7 Years in $6 Million

• Money Launderer for Crypto Thieves Given 5-Year Prison

View all
#Vulnerability Management9 articles

• The Zero-Day Scramble Is Avoidable: Why Attack Surface

• 1 Billion CISA KEV Records Reveal Human-Scale Security Has

• Analysis of 216M Security Findings Shows a 4x Increase in Critical Risk (2026 Report)

View all
#DevOps9 articles

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

• Microsoft Hit by Back-to-Back Outages: M365 Admin Center

• CVE-2026-30836: Step CA SCEP UpdateReq Allows

View all
#canada9 articles

• Telus Digital Confirms Massive Breach After ShinyHunters

• In Other News: Big Tech vs Canada Encryption Bill, Cisco's

• Alleged Kimwolf Botmaster ''Dort'' Arrested, Charged in U.S. and Canada

View all
#Data Exfiltration9 articles

• OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click

• AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable

• Trigona Ransomware Deploys Custom CLI Exfiltration Tool in Active Attacks

View all
#France9 articles

• Cegedim Santé Breach Exposes 15.8 Million French Healthcare

• Elon Musk Fails to Appear for Questioning by French Police

• French Government Agency France Titres Confirms Data Breach

View all
#Dark Reading9 articles

• Trivy Supply Chain Attack Targets CI/CD Secrets

• Blast Radius of TeamPCP Attacks Expands Amid Hacker

• 6-Year Ransomware Campaign Targets Turkish Homes and SMBs

View all
#BEC9 articles

• US Sentences Nigerian National to 7 Years in $6 Million

• FBI: Americans Lost a Record $21 Billion to Cybercrime Last

• FBI: Cybercrime Losses Neared $21 Billion in 2025

View all
#Encryption9 articles

• European Parliament Rejects Extension of CSAM Scanning

• Broken VECT 2.0 Ransomware Acts as a Data Wiper for Large

• In Other News: Big Tech vs Canada Encryption Bill, Cisco's

View all
#Regulation9 articles

• Italian Regulator Fines Financial Giant $36 Million for Data Protection Failures

• European Commission Accuses Meta of Breaching Child Safety

• UK to Require Government ID or Face Scan Before Creating Social Media Accounts

View all
#Source Code9 articles

• Cisco Source Code Stolen in Trivy-Linked Dev Environment

• Trellix Confirms Source Code Breach With Unauthorized

• Trellix Source Code Breach Claimed by RansomHouse Hackers

View all
#Next.js9 articles

• Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts

• Hackers Exploit React2Shell in Automated Credential Theft

• Next.js Creator Vercel Hacked

View all
#KrebsOnSecurity9 articles

• Feds Disrupt IoT Botnets Behind Huge DDoS Attacks

• Germany Doxes "UNKN," Head of RU Ransomware Gangs REvil

• Microsoft Patch Tuesday, March 2026 Edition

View all
#Router Security9 articles

• Authorities Disrupt APT28 Router DNS Hijacks Targeting

• ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI

• Acer Working to Patch Max Severity Zero-Days in Wave 7 Routers

View all
#Backup9 articles

• NAKIVO v11.2: Ransomware Defense, Faster Replication

• New Veeam Vulnerability Exposes Backup Servers to RCE Attacks

• Veeam Backup and Replication RCE Flaw Lets Domain Users Run Remote Code

View all
#SharePoint9 articles

• Microsoft Drops Its Second-Largest Monthly Patch Batch on Record

• Microsoft Issues Patches for SharePoint Zero-Day and 168

• Over 1,300 Microsoft SharePoint Servers Vulnerable to Ongoing Spoofing Attacks

View all
#Vercel9 articles

• Vercel Confirms Breach as Hackers Claim to Be Selling

• Next.js Creator Vercel Hacked

• Vercel Breach Tied to Context AI Hack Exposes Limited

View all
#Sentencing9 articles

• Money Launderer for Crypto Thieves Given 5-Year Prison

• Former Incident Responders Sentenced to 4 Years for Ransomware Attacks on Clients

• Cyber Incident Responders Sentenced to 4 Years for Carrying

View all
#Hugging Face9 articles

• Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

• Fake OpenAI Repository on Hugging Face Pushes Infostealer

• Hugging Face Warns an Autonomous AI Agent Hacked Its Network

View all
#LMS9 articles

• Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

• Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

• KnowledgeDeliver Flaw Exploited as Zero-Day to Install Web

View all
#Web Server9 articles

• 18-Year-Old NGINX Rewrite Module Flaw Enables

• 18-Year-Old NGINX Vulnerability Allows DoS and Potential RCE

• PoC Code Published for Critical NGINX Vulnerability

View all
#DoS9 articles

• 18-Year-Old NGINX Vulnerability Allows DoS and Potential RCE

• Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

• HollowByte: 11-Byte Payload Triggers Memory Bloat DoS on OpenSSL Servers

View all
#Exploitation9 articles

• NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker

• Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

• WP Maps Pro Bug Exploited to Create Admin Accounts on WordPress Sites

View all
#Grafana9 articles

• Grafana Confirms Breach After Hackers Claim They Stole Data

• Grafana Says Stolen GitHub Token Let Hackers Steal Codebase

• Grafana Breach Caused by Missed Token Rotation After

View all
#Information Disclosure9 articles

• CVE-2016-20030: ZKTeco ZKBioSecurity 3.0 Username

• CVE-2025-47813: Wing FTP Server Path Disclosure Enables RCE

• CVE-2026-33669: SiYuan Unauthenticated Document Content

View all
#Dell9 articles

• CVE-2025-36568: Dell PowerProtect Data Domain BoostFS

• CVE-2026-35155: Dell iDRAC10 Race Condition Enables

• Dell ECS and ObjectScale: Hard-Coded Credentials

View all
#code-projects9 articles

• CVE-2026-10178: SQL Injection in Online Music Site 1.0 Admin Panel

• CVE-2026-5017: SQL Injection in code-projects Simple Food

• CVE-2026-5018: SQL Injection in code-projects Simple Food

View all
#CVSS 9.19 articles

• CVE-2026-15265: Tenable Agent Path Traversal — Arbitrary File Write & RCE (CVSS 9.1)

• CVE-2026-26026: GLPI Template Injection Enables

• CVE-2026-31986: Apache OFBiz Hard-Coded Cryptographic Key

View all
#APT288 articles

• APT28 Operation MacroMaze: Russia-Linked Hackers Hit

• Authorities Disrupt APT28 Router DNS Hijacks Targeting

• APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine

View all
#Infrastructure8 articles

• The World's First Transatlantic Fiber Cable Is Being Pulled

• Police Seize 'First VPN' Service Used in Ransomware and Data Theft Attacks

• DeadLock Ransomware Uses Blockchain to Resist Infrastructure Takedown

View all
#Web Application Security8 articles

• LexisNexis Confirms Cloud Breach Exposing 400K User

• Hackers Exploit React2Shell in Automated Credential Theft

• CVE-2026-13550: SQL Injection in itsourcecode Baptism Information Management System 1.0

View all
#Spyware8 articles

• Google: 90 Zero-Days Exploited in 2025 — Enterprise Tech

• DarkSword GitHub Leak Threatens to Turn Elite iPhone

• Bulgaria Allowed Surveillance Tech Firm to Sell Products to Repressive Regimes, Report Says

View all
#n8n8 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

View all
#Veeam8 articles

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

• New Veeam Vulnerability Exposes Backup Servers to RCE Attacks

• Veeam Backup and Replication RCE Flaw Lets Domain Users Run Remote Code

View all
#Automotive8 articles

• Mazda Discloses Security Breach Exposing Employee and Partner Data

• Nissan Says Stolen Data Came from Third-Party Vendor After

• GM to Pay Over $12 Million in Largest-Ever CCPA Fine Over

View all
#GDPR8 articles

• Dutch Court Threatens xAI with Fines Over Grok's

• Italian Regulator Fines Financial Giant $36 Million for Data Protection Failures

• Italian Regulator Fines National Postal Service Orgs $15

View all
#Plugin Security8 articles

• File Read Flaw in Smart Slider Plugin Impacts 500K

• Avada Builder WordPress Plugin Flaws Allow Site Credential

• Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites

View all
#Claude Code8 articles

• Claude Code Source Code Accidentally Leaked in NPM Package

• Claude Code Leak Used to Push Infostealer Malware on GitHub

• Critical Vulnerability in Claude Code Emerges Days After

View all
#Physical Security8 articles

• Adversaries Exploit Vacant Homes to Intercept Mail in Hybrid Cybercrime

• Ransomware Actors Show Up In Person to Steal Law Firm Data

• Japanese Energy Firm Loses Drive with Data of 10.9 Million Clients

View all
#Patient Data8 articles

• 250,000 Affected by Data Breach at Nacogdoches Memorial

• Medtronic Confirms Breach After Hackers Claim 9 Million

• Medtronic Hack Confirmed After ShinyHunters Threatens Data

View all
#Identity8 articles

• Microsoft to Roll Out Entra Passkeys on Windows in Late

• Tycoon2FA Hijacks Microsoft 365 Accounts via Device-Code

• Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

View all
#Entra ID8 articles

• Microsoft to Roll Out Entra Passkeys on Windows in Late

• ConsentFix v3 Automates Azure OAuth Abuse With Mass

• Breach at the Beach: Play the Ultimate Entra ID CTF

View all
#Retail8 articles

• New BlackFile Extortion Group Linked to Surge of Vishing

• Zara Data Breach Exposed Personal Information of 197,000

• 7-Eleven Data Breach Confirmed After ShinyHunters Ransom

View all
#SEC Disclosure8 articles

• American Utility Firm Itron Discloses Breach of Internal IT

• West Pharmaceutical Warns of Ransomware Attack Impacting

• Coca-Cola Fairlife Ransomware Attack Halts All US Dairy Production

View all
#Apache8 articles

• Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS

• AI-Assisted HTTP Terminator Finds Novel Desync Techniques and Apache Zero-Day

• CVE-2025-55017: Apache IoTDB Critical Path Traversal Vulnerability

View all
#Critical Vulnerability8 articles

• Fortinet Warns of Critical RCE Flaws in FortiSandbox and FortiAuthenticator

• Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites

• Cisco Patches Critical Webex Vulnerability Allowing Remote

View all
#Red Hat8 articles

• IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under "Project Lightwell"

• Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

• CVE-2026-10059: Multicluster Engine ClusterCurator Token Escalation (CVSS 9.1)

View all
#Machine Learning8 articles

• Frontier AI Reinforces the Future of Modern Cyber Defense

• Claude Fable 5 Stays Free for Paid Users Until July 19 as Anthropic Buys More Time

• OpenAI Temporarily Relaxes GPT-5.6 Sol Usage Limits Amid Demand Surge

View all
#Unauthenticated RCE8 articles

• Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

• CVE-2026-1579: MAVLink Protocol Unauthenticated Shell Access

• CVE-2026-27053: Critical PHP Object Injection in Broadcast Live Video Plugin

View all
#Networking8 articles

• CVE-2026-40621: ELECOM Wireless LAN Access Point

• CrowdSec: Deploy a Community-Powered Intrusion Prevention System

• How to Set Up BGP Monitoring and Route Alerts

View all
#CIS Benchmarks8 articles

• FortiGate Security Hardening: Best Practices for Enterprise

• Windows Server Hardening: A Complete Security Guide for Enterprises

• AWS Security Hub: Centralized Security Findings

View all
#Monitoring8 articles

• How to Set Up BGP Monitoring and Route Alerts

• Network Monitoring Basics: Detect Threats Before They Spread

• Build a Production Monitoring Stack with Prometheus and Grafana

View all
#EU7 articles

• Google's $32 Billion Wiz Acquisition Clears Final Hurdle as

• CERT-EU: European Commission Hack Exposes Data of 30 EU

• DORA and Operational Resilience: Credential Management as a

View all
#Financial Crime7 articles

• FBI Warns of ATM Jackpotting Surge as Losses Top $20

• Cryptocurrency ATM Giant Bitcoin Depot Reports $3.6 Million

• Cybercriminals Target Accountants to Drain Russian Firms'

View all
#Deepfake7 articles

• ShinyHunters Dumps Harvard and UPenn Data After Ransom

• Deepfake Voice Attacks Are Outpacing Defenses: What

• Weaponized AI: The New Frontier of Fraud and Identity

View all
#Surveillance7 articles

• Persona Source Code Leak Exposes Hidden Biometric

• Citizen Lab: Law Enforcement Used Webloc to Track 500

• Bulgaria Allowed Surveillance Tech Firm to Sell Products to Repressive Regimes, Report Says

View all
#Developer Tools7 articles

• Cline CLI Supply Chain Attack Installs Unauthorized

• Microsoft Suspends Dev Accounts for High-Profile Open

• Critical Gemini CLI Flaw Enabled Host Code Execution

View all
#MFA Bypass7 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Why Simple Breach Monitoring Is No Longer Enough

• Tycoon2FA Hijacks Microsoft 365 Accounts via Device-Code

View all
#Samsung7 articles

• Windows 11 February Update Breaks C:\ Drive Access on Samsung PCs

• Microsoft Shares Fix for Windows C: Drive Access Issues on Samsung PCs

• CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal

View all
#Cyberattack7 articles

• Stryker Cyberattack Wiped Tens of Thousands of Devices — No

• Moldova's Health Insurance Agency Reports Possible Data

• Cyberattack on Russian Tech Firm Astral Disrupts Business and Government Services for a Week

View all
#Zimbra7 articles

• CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC

• Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks

• Zimbra Urges Customers to Patch Critical Web Client XSS Flaw Exploited in the Wild

View all
#Qilin7 articles

• Malaysia Airlines Listed by Qilin Ransomware Group

• Die Linke German Political Party Confirms Data Stolen by Qilin Ransomware

• CISA Gives Feds 3 Days to Patch Check Point VPN Bug Exploited as Zero-Day

View all
#LiteLLM7 articles

• Supply Chain Attack Hits Widely-Used AI Package, Risking

• Mercor Confirms Security Incident Tied to LiteLLM Supply

• The Good, the Bad and the Ugly in Cybersecurity – Week 14

View all
#Exploit7 articles

• AI Slashes Cyberattack Exploit Timelines From Years to Days

• New Linux 'Dirty Frag' Zero-Day Gives Root on All Major

• Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

View all
#AI Regulation7 articles

• Dutch Court Threatens xAI with Fines Over Grok's

• UK Government Threatens Tech Bosses With Jail Time Over AI

• Elon Musk Fails to Appear for Questioning by French Police

View all
#Data Protection7 articles

• Italian Regulator Fines Financial Giant $36 Million for Data Protection Failures

• Italian Regulator Fines National Postal Service Orgs $15

• Coupang Hit with Record $409 Million Data Breach Fine in South Korea

View all
#Axios7 articles

• Attack on Axios Developer Tool Threatens Widespread

• Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

• Axios NPM Package Breached in North Korean Supply Chain

View all
#Lazarus Group7 articles

• Drift Crypto Platform Confirms $280 Million Stolen as

• KelpDAO Suffers $290 Million Heist Tied to Lazarus Hackers

• Crypto Infrastructure Company Blames $290 Million Theft on North Korean Hackers

View all
#Weekly Roundup7 articles

• ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache

• In Other News: Satellite Cybersecurity Act, $90K Chrome

• ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force

View all
#AI Policy7 articles

• Commerce Setting Up New AI Export Regime to Push Adoption

• Anthropic Disables Fable 5 and Mythos 5 After U.S. Government Export Control Decree

• Anthropic Confirms Fable 5 and Mythos 5 Offline to Comply With US Export Controls

View all
#Windows Server7 articles

• Microsoft Releases Emergency Updates to Fix Windows Server

• Microsoft: Domain Controller Lookup May Fail on Windows

• Microsoft June 2026 Updates Break Recycle Bin Confirmation Prompts on All Windows Versions

View all
#Web Hosting7 articles

• cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug

• Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now

• Critical cPanel Flaw Mass-Exploited in 'Sorry' Ransomware

View all
#PAN-OS7 articles

• PAN-OS RCE Exploit Under Active Use Enabling Root Access

• ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI

• Palo Alto GlobalProtect VPN Auth Bypass Flaw Now Exploited in Attacks

View all
#Self-Hosted7 articles

• Gitea Vulnerability Exposes Private Container Images without Authentication

• Hackers Exploit Critical Auth Bypass in Official Gitea Docker Image

• Coolify CVE-2026-34037: CVSS 9.9 IDOR Enables Cross-Team Resource Takeover

View all
#Threat Detection7 articles

• Only 10% of SOCs Say They're Getting Excellent Value From AI — What the Second Wave Must Deliver

• How to Deploy Falco for Kubernetes Runtime Security

• How to Deploy Wazuh SIEM/XDR for Unified Security Monitoring

View all
#AI Safety7 articles

• OpenAI Previews GPT-5.6 Sol Under Government-Gated Rollout with Stronger Cyber Safeguards

• Anthropic's Claude Breached 3 Orgs, Uploaded PyPI Malware During Tests

• Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

View all
#Hardcoded Credentials7 articles

• CVE-2016-20026: ZKTeco ZKBioSecurity 3.0 Hardcoded Tomcat

• CVE-2025-63823: My Safetipin Android App Exposes Hardcoded Credentials (CVSS 9.8)

• CVE-2026-11849: IRM-IEI Remote Management Hardcoded Credentials

View all
#Missing Authorization7 articles

• CVE-2018-25391: HaPe PKH 1.1 Unauthenticated Record Deletion via Missing Authorization

• CVE-2025-10656: WooCommerce Plugin Missing Authorization Allows Unauthenticated Admin Account Creation

• Critical RCE in Hitachi Vantara Pentaho via Unrestricted

View all
#GeoVision7 articles

• CVE-2026-12485: GeoVision GV-I/O Box 4E UDP Stack Overflow (IP Address Field)

• CVE-2026-12486: GeoVision GV-I/O Box 4E OS Command Injection via libNetSetObj.so

• CVE-2026-12846: GeoVision GV-I/O Box 4E UDP Stack Overflow (Net Mask Field)

View all
#CWE-947 articles

• CVE-2026-12866: expr-eval npm Package Enables Arbitrary Code Execution via toJSFunction()

• CVE-2026-1540: Spam Protect CF7 WordPress Plugin PHP Log RCE

• CVE-2026-22679: Weaver E-cology 10.0 Unauthenticated Remote

View all
#Heap Buffer Overflow7 articles

• CVE-2026-20889: LibRaw x3f_thumb_loader Heap Buffer

• CVE-2026-20911: LibRaw HuffTable::initval Heap Buffer

• CVE-2026-21413: LibRaw lossless_jpeg_load_raw Heap Buffer

View all
#Traefik7 articles

• CVE-2026-35051: Traefik ForwardAuth Authentication Bypass

• CVE-2026-39858: Traefik Forwarded-Header Sanitization

• Multi-Stack Docker Infrastructure with Traefik and Authentik

View all
#Geopolitics6 articles

• WEF Global Cybersecurity Outlook 2026 Warns of 'Permanent

• Pro-Russian Hacktivists Launch Sustained Cyber Campaign

• Commerce Setting Up New AI Export Regime to Push Adoption

View all
#DeepSeek6 articles

• Anthropic Exposes Industrial-Scale AI Distillation Attacks

• AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android

• Chinese Threat Actor Uses DeepSeek and Hermes Agent to Launch Fully Autonomous Cyberattacks

View all
#Europe6 articles

• APT28 Operation MacroMaze: Russia-Linked Hackers Hit

• Italian Regulator Fines Financial Giant $36 Million for Data Protection Failures

• Europe Evolves Into Ransomware's Favorite Region

View all
#BlackCat6 articles

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

• Former Ransomware Negotiator Pleads Guilty to BlackCat

• US Ransomware Negotiators Get 4 Years in Prison Over

View all
#Workflow Automation6 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

View all
#Federal6 articles

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• CISA Gives Federal Agencies Four Days to Patch Actively

View all
#Backup & Replication6 articles

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

• Veeam Backup & Replication Auth RCE — CVE-2026-21666

• Veeam Backup & Replication 2nd Auth RCE — CVE-2026-21667

View all
#Enterprise Backup6 articles

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

• Veeam Backup & Replication Auth RCE — CVE-2026-21666

• Veeam Backup & Replication 2nd Auth RCE — CVE-2026-21667

View all
#VS Code6 articles

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

• Malicious KICS Docker Images and VS Code Extensions Hit

• GitHub Links Repo Breach to TanStack npm Supply-Chain Attack

View all
#Windows 116 articles

• Windows 11 February Update Breaks C:\ Drive Access on Samsung PCs

• Microsoft Now Force-Upgrades Unmanaged Windows 11 24H2 PCs

• Microsoft Rolls Out Revamped Windows Insider Program

View all
#Interpol6 articles

• Operation Synergia III: Police Sinkhole 45,000 IPs in Global Cybercrime Crackdown

• INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific

• Ransomware Thugs Masquerade as Interpol to Entice Small Biz

View all
#Shadow AI6 articles

• Shadow AI Is Everywhere. Here's How to Find and Secure It.

• Learning from the Vercel Breach: Shadow AI and OAuth Sprawl

• 5 Steps to Managing Shadow AI Tools Without Slowing Down

View all
#Citrix6 articles

• Citrix Urges Admins to Patch NetScaler Flaws as Soon as

• Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active

• Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks

View all
#Magento6 articles

• PolyShell Attacks Target 56% of All Vulnerable Magento

• WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

• Hackers Use Pixel-Large SVG Trick to Hide Credit Card

View all
#National Security6 articles

• FCC Bans Import of Foreign-Made Consumer Routers Over

• New U.S. Cyber Force Would Cost Up to $11 Billion to Start, Commission Says

• Anthropic Disables Fable 5 and Mythos 5 After U.S. Government Export Control Decree

View all
#WebSocket6 articles

• New RoadK1ll WebSocket Implant Used to Pivot on Breached

• Coolify CVE-2026-34047: Terminal WebSocket Authorization Bypass (CVSS 9.9)

• Coolify CVE-2026-34048: Low-Privilege Terminal Escalation via WebSocket (CVSS 9.9)

View all
#Supply Chain Security6 articles

• The State of Secrets Sprawl 2026: 9 Takeaways for CISOs

• OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds

• New Initiative Tackles Security for End-of-Life Open Source Software

View all
#Southeast Asia6 articles

• Three China-Linked Clusters Target Southeast Asian

• DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets

• Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown

View all
#Bitcoin6 articles

• Google Slashes Quantum Resource Requirements for Breaking

• Hackers Steal $3.6 Million from Crypto ATM Giant Bitcoin

• ShinyHunters Data Leaks Fuel $2,000 Sextortion Email Scam

View all
#Crypto6 articles

• Crypto Platform Drift Suspends Services After Hundreds of Millions Stolen

• Polymarket Customers Lose $3 Million in Supply-Chain Attack

• $3 Million Reportedly Stolen in Polymarket Hack

View all
#Pre-Auth6 articles

• New Progress ShareFile Flaws Can Be Chained in Pre-Auth RCE

• vBulletin Fixes Critical Pre-Auth RCE Flaw with Public Exploit

• BeyondTrust Remote Support Pre-Authentication RCE Under

View all
#Supply Chain Attack6 articles

• Axios npm Hack Used Fake Teams Error Fix to Hijack

• Suspicious Polyfill Login Prompts Pop Up on Toshiba, Muji Websites

• Polymarket Customers Lose $3 Million in Supply-Chain Attack

View all
#CyberScoop6 articles

• Trump Budget Proposal Would Cut Hundreds of Millions More

• Why the Axios Attack Proves AI Is Mandatory for Supply

• Former DigitalMint Ransomware Negotiator Pleads Guilty to $75.3M Extortion Scheme

View all
#Credentials6 articles

• The Hidden Cost of Recurring Credential Incidents

• DORA and Operational Resilience: Credential Management as a

• FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices

View all
#Risk Management6 articles

• The Hidden Cost of Recurring Credential Incidents

• One Missed Threat Per Week: What 25M Alerts Reveal About

• Why Chargebacks Are Just One Piece of the Fraud Puzzle

View all
#Export Controls6 articles

• Commerce Setting Up New AI Export Regime to Push Adoption

• Anthropic Disables Fable 5 and Mythos 5 After U.S. Government Export Control Decree

• Anthropic Confirms Fable 5 and Mythos 5 Offline to Comply With US Export Controls

View all
#Microsoft Edge6 articles

• Microsoft Teams Right-Click Paste Broken by Edge Update Bug

• ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days

• Google and Microsoft Pull ModHeader After Hidden Tracker Found in 1.6M-Install Extension

View all
#C26 articles

• Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

• 'Underminr' Vulnerability Lets Attackers Hide Malicious

• Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

View all
#Firefox6 articles

• Firefox Vulnerability Allows Tor User Fingerprinting Across

• Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities

• CVE-2026-5731: Firefox and Thunderbird Critical Memory

View all
#Personal Data6 articles

• Home Security Giant ADT Data Breach Affects 5.5 Million

• DocketWise Data Breach Impacts 143,000 Individuals

• IMA Diligence Services Data Breach Impacts 525,000 People

View all
#Meta6 articles

• European Commission Accuses Meta of Breaching Child Safety

• Hackers Used Meta's AI Support Bot to Seize Instagram Accounts

• WhatsApp Is Finally Getting Usernames to Help Keep Phone Numbers Private

View all
#EPMM6 articles

• CISA Gives Federal Agencies Four Days to Patch Actively

• Ivanti Customers Confront Yet Another Actively Exploited

• Ivanti Warns of New EPMM Flaw Exploited in Zero-Day Attacks

View all
#Kernel6 articles

• New Linux 'Dirty Frag' Zero-Day Gives Root on All Major

• Making Vulnerable Drivers Exploitable Without Hardware: The

• Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks

View all
#LLM Security6 articles

• Ollama Out-of-Bounds Read Flaw Allows Remote Process Memory

• New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

• JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware

View all
#Palo Alto Networks6 articles

• PAN-OS RCE Exploit Under Active Use Enabling Root Access

• Palo Alto GlobalProtect VPN Auth Bypass Flaw Now Exploited in Attacks

• PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

View all
#Energy Sector6 articles

• China's 'FamousSparrow' APT Nests in South Caucasus Energy

• Japanese Energy Firm Loses Drive with Data of 10.9 Million Clients

• Origin Energy Data Breach Exposes Millions of Australian Customers

View all
#BitLocker6 articles

• Windows BitLocker Zero-Day Gives Access to Protected

• Researcher Drops YellowKey, GreenPlasma Windows Zero-Days

• Windows Zero-Days Expose BitLocker Bypasses and CTFMON

View all
#Heap Overflow6 articles

• 18-Year-Old NGINX Rewrite Module Flaw Enables

• CVE-2026-40492: SAIL XWD Codec Heap Buffer Overflow (CVSS

• CVE-2026-40494: SAIL TGA Codec RLE Decoder Asymmetric

View all
#PraisonAI6 articles

• PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours

• CVE-2026-39888: PraisonAI Sandbox Escape Enables Remote

• CVE-2026-39890: PraisonAI YAML Injection Achieves Remote

View all
#Vulnerability Disclosure6 articles

• Microsoft Rejects Critical Azure Vulnerability Report, No

• Microsoft Says Zero-Day Public Releases Are 'Never Justifiable' as Researcher Threatens More Drops

• Microsoft Says It Will Not Pursue Security Researchers After Zero-Day Backlash

View all
#South Korea6 articles

• Can Laws Stop Deepfakes? South Korea Aims to Find Out

• Coupang Hit with Record $409 Million Data Breach Fine in South Korea

• South Korea Discloses Data Breach Impacting Diplomats Worldwide

View all
#Research6 articles

• Making Vulnerable Drivers Exploitable Without Hardware: The

• Security of 100 AI Agents Tested and Ranked – What You Need to Know

• Leak Confirms OpenAI Is Testing a ChatGPT for Science Subscription

View all
#Credential Stuffing6 articles

• Dashlane Password Manager Users Locked Out by Brute Force Attacks

• Minnesota Man Known as 'Snoopy' Sentenced in DraftKings Hack

• Chick-fil-A Discloses Data Breach After Credential Stuffing Attacks

View all
#AI Agents6 articles

• Security of 100 AI Agents Tested and Ranked – What You Need to Know

• Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

• Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

View all
#Check Point6 articles

• CISA Gives Feds 3 Days to Patch Check Point VPN Bug Exploited as Zero-Day

• Check Point VPN Zero-Day Exploited Since Early May by Qilin Ransomware

• Check Point Patches SmartConsole Zero-Day Exploited in Attacks

View all
#Secrets Management6 articles

• Novo Nordisk Breach Exposes Software Development Pipeline Risk

• SailPoint to Acquire Entro in Reported $200 Million Deal

• Lessons Learned from CISA's Recent GitHub Leak

View all
#WhatsApp6 articles

• WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs

• WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

• Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

View all
#IDOR6 articles

• Data Exposure Flaws in Dify AI Platform Put 1 Million+ App Tenants at Risk

• Coolify CVE-2026-34037: CVSS 9.9 IDOR Enables Cross-Team Resource Takeover

• CVE-2026-25197: IDOR Flaw Lets Authenticated Users Access

View all
#Signal6 articles

• Russia Used Social Engineering to Breach Prominent Messaging Accounts, Ukraine Says

• Ukraine and FBI Expose Russian Intelligence Campaign Stealing Signal Credentials via Fake SMS

• FBI: Russian Hackers Now Target Signal Backup Recovery Keys

View all
#Telegram6 articles

• Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

• RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

• Hackers Hijack Russian Journalist Sobchak's Telegram Channels via Email Breach, Claim 350 GB Stolen

View all
#Load Balancer6 articles

• Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

• Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

• CVE-2026-47868: VMware Avi Load Balancer Local Privilege Escalation

View all
#supply-chain6 articles

• 'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat

• Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

• China-Linked Storm-1175 Turns N-able N-central Into MSP Ransomware Launchpad

View all
#Google Chrome6 articles

• Google and Microsoft Pull ModHeader After Hidden Tracker Found in 1.6M-Install Extension

• Google Chrome Critical Update Patches High-Severity Code

• Google Patches Actively Exploited Chrome Zero-Day

View all
#Firewall6 articles

• Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

• The Network Has Become the Control Plane for AI Security

• FBI, South Korea Warn of Gunra Ransomware Gang Targeting Critical Infrastructure

View all
#CVSS 10.06 articles

• Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

• UniFi OS Improper Access Control — Unauthorized System

• CVE-2026-47131: vm2 Sandbox Escape via Buffer Prototype Hijack (CVSS 10.0)

View all
#Session Hijacking6 articles

• New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

• CVE-2026-2342: ValeApp Stored Cross-Site Scripting (CVSS 9.3)

• Critical Session Hijacking via Auth Bypass in Akilli

View all
#ColdFusion6 articles

• Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic

• CVE-2026-47928: Adobe ColdFusion Critical RCE — CVSS 9.6

• CVE-2026-48276: Adobe ColdFusion Critical File Upload RCE (CVSS 10.0)

View all
#Database Security6 articles

• CVE-2018-25272: ELBA5 5.8.0 RCE via Default Database

• CVE-2026-19001: MongoDB BI Connector ODBC Driver Buffer Overflow (CVSS 9.8)

• CVE-2026-24013: Apache IoTDB Authentication Bypass via Forged Session ID

View all
#REST API6 articles

• CVE-2021-47933: WordPress MStore API 2.0.6 Arbitrary File

• CVE-2026-1830: WordPress Quick Playground Plugin RCE via Unauthenticated File Upload

• CVE-2026-20223: Cisco Secure Workload REST API Auth Bypass

View all
#JWT6 articles

• CVE-2025-57735: Apache Airflow JWT Token Not Invalidated on Logout

• CVE-2026-1114: lollms JWT Weak Secret Key Allows Admin

• CVE-2026-31946: Critical JWT Signature Verification Bypass

View all
#SAML6 articles

• PicketLink SAML Authentication Bypass — Forged Assertions Accepted Without Validation

• CVE-2026-15013: WordPress SAML SSO Plugin — Algorithm Confusion Auth Bypass

• CVE-2026-15981: WordPress SAML SSO Authentication Bypass (CVSS 9.8)

View all
#CWE-2876 articles

• CVE-2026-12183: Critical Auth Bypass in Gas Station Automation System

• CVE-2026-12492: WooCommerce OTP Login Plugin Auth Bypass — Full Admin Takeover

• CVE-2026-14205: WP Events Manager Plugin Allows Fraudulent Paid Event Bookings via Payment Bypass

View all
#Password Reset6 articles

• CVE-2026-13498: SQL Injection in Restaurant Management System via Password Reset

• CVE-2026-14364: TrueBooker WordPress Plugin Account Takeover via Password Reset Bypass

• CVE-2026-24467: OpenAEV Password Reset Account Takeover

View all
#PHP Object Injection6 articles

• CVE-2026-14637: PHP Deserialization RCE in CodeIgniter Ecommerce Bootstrap Shopping Cart

• CVE-2026-15962: PHP Object Injection in Fluent Forms Pro (CVSS 8.8)

• CVE-2026-27053: Critical PHP Object Injection in Broadcast Live Video Plugin

View all
#Wazuh6 articles

• CVE-2026-25769: Wazuh Critical RCE via Insecure

• CVE-2026-25770: Wazuh Privilege Escalation to Root via Cluster Protocol File Write

• CVE-2026-56699: Critical NDJSON Injection in Wazuh Manager (CVSS 10.0)

View all
#CVSS Critical6 articles

• CVE-2026-37431: Beauty Parlour Management System SQL

• CVE-2026-38158: Critical SQL Injection in UReport v2.2.9 (CVSS 9.8)

• CVE-2026-41583: ZEBRA Zcash Node Consensus Rule Bypass

View all
#IP Camera6 articles

• GeoVision LPC Camera Critical RCE via thttpd Buffer Overflow (CVE-2026-57878)

• GeoVision LPC Camera Critical RCE via ssvr RTSP Auth Buffer Overflow (CVE-2026-57879)

• GeoVision LPC Camera Critical RCE via ssvr RTSP Digest Auth Buffer Overflow (CVE-2026-57880)

View all
#Legal5 articles

• Ex-L3Harris Executive Pleads Guilty to Selling Eight

• LexisNexis Confirms Cloud Breach Exposing 400K User

• Microsoft's Zero-Day Legal Threats Spark Backlash

View all
#Data Extortion5 articles

• Ransomware in 2026: Data-Only Extortion Replaces Encryption

• Evolution of Ransomware: Multi-Extortion Ransomware Attacks

• Tata Electronics Confirms Cyberattack; World Leaks Exposes Apple Manufacturing IP

View all
#Scattered Spider5 articles

• Scattered Lapsus$ ShinyHunters Alliance Hits 100+

• In Other News: Scattered Spider Member Arrested, SOC

• Grafana Confirms Breach After Hackers Claim They Stole Data

View all
#Deepfakes5 articles

• AI-Driven Threats Accelerate: Agentic Attacks, Model

• UK Government Threatens Tech Bosses With Jail Time Over AI

• Here's How the FTC Plans to Enforce the Take It Down Act

View all
#Vishing5 articles

• ShinyHunters Dumps Harvard and UPenn Data After Ransom

• New BlackFile Extortion Group Linked to Surge of Vishing

• Deepfake Voice Attacks Are Outpacing Defenses: What

View all
#Gemini5 articles

• PromptSpy: First Android Malware to Weaponize Generative AI

• Critical Gemini CLI Flaw Enabled Host Code Execution

• Google Gemini CLI Jailbroken and Used as a Hacking Agent to Run a Malware Botnet

View all
#Hacktivism5 articles

• Pro-Russian Hacktivists Launch Sustained Cyber Campaign

• Operation Epic Fury Triggers Unprecedented Cyber Escalation

• Bearlyfy Hits Russian Firms with Custom GenieLocker

View all
#Sanctions5 articles

• U.S. Treasury Sanctions Russian Zero-Day Broker Operation

• Russian Spies Aggressively Targeting Western Technology as Sanctions Bite

• The U.S. Sanctions Nobitex Crypto Exchange Used by Ransomware

View all
#Telecommunications5 articles

• The World's First Transatlantic Fiber Cable Is Being Pulled

• Google Disrupts Massive Chinese Espionage Campaign

• FCC Proposes $4.5 Million Fine for Voice Provider Hosting

View all
#MongoDB5 articles

• IDMerit KYC Data Breach Exposes 1 Billion Records Across 26

• CVE-2026-19001: MongoDB BI Connector ODBC Driver Buffer Overflow (CVSS 9.8)

• CVE-2026-45688: Rocket.Chat CAS Login MongoDB Operator Injection (CVSS 9.1)

View all
#AiTM5 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

• Misconfigured Server Exposes Three Evilginx Phishing Ops Targeting M365

View all
#Extradition5 articles

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

• Ukrainian National Pleads Guilty to Role in Conti Ransomware Operation

• Alleged Scattered Spider Hacker Peter Stokes Extradited to the United States

View all
#PHI5 articles

• Cognizant TriZetto Breach Exposes Health Data of 3.4

• Hims & Hers Breach Exposes the Most Sensitive Kinds of Patient PHI

• 716,000 Impacted by OpenLoop Health Data Breach

View all
#Mandiant5 articles

• Cognizant TriZetto Breach Exposes Health Data of 3.4

• ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities

• Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack

View all
#CRM5 articles

• ShinyHunters Claims Mass Data Theft From 400 Firms via Salesforce Aura

• Wesco Confirms Security Incident After ExfilSquad Claims 2.6M Record Theft

• Over 1,000 Charities Hit by Beacon CRM Data Breach

View all
#SaaS Security5 articles

• Shadow AI Is Everywhere. Here's How to Find and Secure It.

• Shadow AI in SaaS: How Hidden AI Agents Are Enabling

• Video Service Vimeo Confirms Anodot Breach Exposed User Data

View all
#SGLang5 articles

• AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable

• SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious

• CVE-2026-14890: SGLang ZeroMQ Unauthenticated RCE via Pickle Deserialization

View all
#Regulatory5 articles

• Microsoft Halts Forced Global Rollout of Microsoft 365

• FCC Proposes New Rule to Further Crack Down on Illegal

• GM to Pay Over $12 Million in Largest-Ever CCPA Fine Over

View all
#Kimwolf5 articles

• DoJ Disrupts 3 Million-Device IoT Botnets Behind Record

• Alleged Kimwolf Botmaster ''Dort'' Arrested, Charged in U.S. and Canada

• Canadian Man Arrested and Charged for Running KimWolf DDoS

View all
#Initial Access Broker5 articles

• Russian Hacker Who Helped Yanluowang Ransomware Gang Gets

• FortiBleed: Russian IAB Harvested 110 Million Credentials from 430,000 FortiGate Firewalls

• FortiBleed: 5-Stage Attack Chain Behind 110 Million Credential Heist on FortiGate Firewalls

View all
#F55 articles

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• Hackers Now Exploit Critical F5 BIG-IP Flaw in Attacks

• F5 BIG-IP Vulnerability Reclassified from DoS to RCE Under

View all
#BIG-IP5 articles

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• Hackers Now Exploit Critical F5 BIG-IP Flaw in Attacks

• F5 BIG-IP Vulnerability Reclassified from DoS to RCE Under

View all
#Nation State5 articles

• Iran-Linked Hackers Breach FBI Director's Personal Email

• Researchers Uncover Pre-Stuxnet 'fast16' Malware Targeting

• UK Cyberspying Chief Calls AI 'an Unstoppable Force' and Warns About Russia

View all
#Post-Quantum5 articles

• Google Slashes Quantum Resource Requirements for Breaking

• Kyber Ransomware Gang Uses Post-Quantum Encryption to Target Windows and ESXi

• Apple Open-Sources Quantum-Resistant Encryption Code

View all
#Wiper5 articles

• Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations

• Broken VECT 2.0 Ransomware Acts as a Data Wiper for Large

• Vect 2.0 Ransomware Acts as Wiper Thanks to Design Error

View all
#Credential Security5 articles

• Why Simple Breach Monitoring Is No Longer Enough

• Microsoft Backpedals: Edge to Stop Loading Cleartext

• MokN Raises $15 Million for Phish-Back Platform

View all
#Apache ActiveMQ5 articles

• 13-Year-Old Bug in ActiveMQ Lets Hackers Remotely Execute

• ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache

• CISA Flags Apache ActiveMQ Flaw as Actively Exploited in Attacks

View all
#Patch Management5 articles

• 1 Billion CISA KEV Records Reveal Human-Scale Security Has

• 73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation

• CISA Orders Feds to Patch Max Severity Joomla Plugin Flaw by Friday

View all
#Virtualization5 articles

• Payouts King Ransomware Uses QEMU Virtual Machines to Bypass Endpoint Security

• NAKIVO v11.2: Ransomware Defense, Faster Replication

• CVE-2026-25199: Apache CloudStack Proxmox Extension Allows

View all
#Windows Defender5 articles

• Three Microsoft Defender Zero-Days Actively Exploited; Two

• Microsoft Warns of New Defender Zero-Days Exploited in Attacks

• Microsoft Warns of Two Actively Exploited Defender

View all
#Disaster Recovery5 articles

• NAKIVO v11.2: Ransomware Defense, Faster Replication

• Azure Backup: VMs, Files, and SQL with Recovery Services

• Implementing a Robust Backup Strategy: The 3-2-1 Rule

View all
#NIST5 articles

• NIST to Stop Rating Non-Priority Flaws Due to Volume

• Federal Audit Reveals NIST's NVD Is Plagued by Poor Planning and Duplication

• CISA Mandates Full Zero Trust Architecture for Federal

View all
#Regulatory Fine5 articles

• Italian Regulator Fines National Postal Service Orgs $15

• UK Fines Water Supplier $1.3M for Exposing Data of 664K

• Coupang Hit with Record $409 Million Data Breach Fine in South Korea

View all
#Password Manager5 articles

• Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain

• Dashlane Password Manager Users Locked Out by Brute Force Attacks

• Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

View all
#Mozilla5 articles

• Firefox Vulnerability Allows Tor User Fingerprinting Across

• CVE-2026-5731: Firefox and Thunderbird Critical Memory

• CVE-2026-6748: Critical Uninitialized Memory Flaw in Firefox and Thunderbird Web Codecs

View all
#Auth Bypass5 articles

• Hackers Exploit RCE Flaws in Qinglong Task Scheduler for Cryptomining

• Gitea Vulnerability Exposes Private Container Images without Authentication

• CVE-2026-18248: Fastify AWS Lambda Auth Bypass Allows Privilege Escalation

View all
#MSP5 articles

• Top Five Sales Challenges Costing MSPs Cybersecurity Revenue

• CVE-2026-18577: N-able N-central Authentication Bypass and Account Takeover

• NinjaOne Scripting: PowerShell Automation Library

View all
#AI Platform5 articles

• Fake OpenAI Repository on Hugging Face Pushes Infostealer

• Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

• CVE-2025-34291: Langflow Origin Validation Error

View all
#Security Operations5 articles

• One Missed Threat Per Week: What 25M Alerts Reveal About

• Exaforce Raises $125 Million for Agentic SOC Platform

• Only 10% of SOCs Say They're Getting Excellent Value From AI — What the Second Wave Must Deliver

View all
#Security Update5 articles

• Microsoft May 2026 Patch Tuesday Fixes 120 Flaws, No

• FFmpeg Fixes PixelSmash Flaw in Widely Used Video Decoder

• Microsoft Fixes AutoGen Studio Flaw That Enabled Code Execution

View all
#Network-Security5 articles

• Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited

• Cisco Zero-Day Under Ongoing Attack by Persistent Threat

• Suricata IDS/IPS Deployment: From Install to Active Threat

View all
#PoC5 articles

• PoC Code Published for Critical NGINX Vulnerability

• MiniPlasma Windows 0-Day Enables SYSTEM Privilege

• Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

View all
#LiteSpeed5 articles

• LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run

• CISA Gives Feds 4 Days to Patch Actively Exploited cPanel Plugin Flaw

• CISA Urges Immediate Patching of Exploited LiteSpeed cPanel

View all
#Web Shell5 articles

• Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

• KnowledgeDeliver Flaw Exploited as Zero-Day to Install Web

• KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

View all
#OWASP5 articles

• Open Source DockSec Uses AI to Cut Through Vulnerability

• OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds

• Vague Task, Total Access: When AI Delegation Becomes a Security Risk

View all
#ICS Security5 articles

• Exposed Fuel Tank Gauges Under Attack in the US

• Russian Hackers Breached Polish Energy Plant via Private APN in World-First DER Cyberattack

• In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

View all
#Memory Safety5 articles

• Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities

• CVE-2026-5731: Firefox and Thunderbird Critical Memory

• CVE-2026-6748: Critical Uninitialized Memory Flaw in Firefox and Thunderbird Web Codecs

View all
#Australia5 articles

• Australian Sugar Producer Works to Restore Operations After Ransomware Attack

• Origin Energy Data Breach Exposes Millions of Australian Customers

• Origin Energy Data Breach: Fired Employee's Credentials Expose Up to 2 Million Australian Customers

View all
#Data Exposure5 articles

• Data Exposure Flaws in Dify AI Platform Put 1 Million+ App Tenants at Risk

• Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

• CVE-2025-15609: Fortis for WooCommerce Plugin Leaks API

View all
#social-engineering5 articles

• WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

• Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

• Teen Suspect in Scattered Spider Hacks Is Extradited to US

View all
#SSH5 articles

• Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

• CVE-2025-15638: Net::Dropbear Bundles Vulnerable

• CVE-2026-58065: Apache Airflow Git Provider Disables SSH Host Key Verification

View all
#threat-intelligence5 articles

• Chinese LLMs Broaden the Gap Between Attackers & Defenders

• China-Linked Storm-1175 Turns N-able N-central Into MSP Ransomware Launchpad

• CrowdSec: Deploy a Community-Powered Intrusion Prevention System

View all
#AI Tools5 articles

• CISA Orders Feds to Prioritize Patching Langflow Auth Bypass Flaw

• 2-Click Cursor Exploit Enables Dev Environment Takeover

• Trojanized MCP Server Deploys StealC Infostealer Targeting

View all
#MFA5 articles

• Identity Attacks Overtake Exploits as Top Ransomware Cause

• The Microsoft 365 Security Baseline Every Small Business Should Have

• Conditional Access Policies: Zero Trust with Entra ID

View all
#Outage5 articles

• OpenAI Confirms ChatGPT Is Down Worldwide — ~50-Minute Global Outage

• Microsoft Blames Massive Microsoft 365 Outage on Automated Maintenance Bug

• Cloudflare BGP Routing Error Cascades Across AWS, X, and More

View all
#Denial of Service5 articles

• Cisco Warns of ASA and FTD VPN Flaw Actively Exploited to Crash Firewalls

• CVE-2018-25169: Denial of Service Vulnerability Catalogued

• CVE-2026-20349: Cisco ASA and FTD Heap Inspection Vulnerability

View all
#Ecommerce5 articles

• CVE-2020-37168: Systempay Weak Crypto Allows Payment

• CVE-2021-47923: OpenCart 3.0.3.8 Session Fixation Enables

• CVE-2025-65336: Critical SQL Injection in Fruits Bazar PHP Ecommerce

View all
#MLflow5 articles

• CVE-2025-15036: MLflow Path Traversal in Archive Extraction

• CVE-2025-15379: MLflow Command Injection in Model Serving

• CVE-2026-0596: MLflow Command Injection via Unsanitized

View all
#Remote Exploit5 articles

• CVE-2026-10263: SQL Injection in SourceCodester Computer Repair Shop Management System

• CVE-2026-14732: SQL Injection in SourceCodester Timetabling System via /edit_exam.php

• CVE-2026-14733: SQL Injection in SourceCodester Timetabling System via /edit_coursea.php

View all
#CVSS 9.65 articles

• CVE-2026-11807: Critical Authorization Bypass in Event-Driven Ansible WebSocket API

• CVE-2026-24303: Microsoft Partner Center Privilege

• CVE-2026-2611: MLflow 3.9.0 Improper Origin Validation

View all
#Directory Traversal5 articles

• CVE-2026-13339: CubeWP Framework WordPress Plugin Directory Traversal (CVSS 7.5)

• CVE-2026-18352: WordPress User Access Manager Directory Traversal

• CVE-2026-34909 — UniFi OS Path Traversal Leading to Account

View all
#itsourcecode5 articles

• CVE-2026-14688: SQL Injection in itsourcecode Hotel Management Admin Login

• CVE-2026-3730: SQL Injection in itsourcecode Free Hotel

• CVE-2026-3740: SQL Injection in itsourcecode University

View all
#CWE-5025 articles

• CVE-2026-25449: Critical Object Injection in Shinetheme

• CVE-2026-25769: Wazuh Critical RCE via Insecure

• CVE-2026-48207: Apache Fury PyFury Deserialization RCE

View all
#Identity Provider5 articles

• CVE-2026-29067: ZITADEL Password Reset Poisoned by Host Header Injection

• ZITADEL Critical XSS in SAML Endpoint Enables 1-Click

• CVE-2026-29192: ZITADEL Stored XSS via Default Redirect URI

View all
#PKI5 articles

• CVE-2026-30836: Step CA SCEP UpdateReq Allows

• CVE-2026-9648: X.509 NameConstraints Bypass in crypton-x509-validation

• HashiCorp Vault: Centralized Secrets Management for Modern

View all
#Input Validation5 articles

• UniFi OS Command Injection via Improper Input Validation

• CVE-2026-47367: UID Enterprise Agent Command Injection via Improper Input Validation

• CVE-2026-47369: UniFi OS Privilege Escalation via Improper Input Validation

View all
#Broadcom5 articles

• CVE-2026-47865: Critical Authentication Bypass in VMware Avi Load Balancer

• CVE-2026-47866: Authorization Bypass in VMware Avi Load Balancer

• CVE-2026-47867: Remote Code Execution via Code Injection in VMware Avi Load Balancer

View all
#Containers5 articles

• Container Security Scanning with Trivy: Images, IaC, and CI/CD

• Docker Security Hardening: Locking Down Container Environments

• Docker Security Fundamentals: Protecting Your Containers

View all
#threat-detection5 articles

• Suricata IDS/IPS Deployment: From Install to Active Threat

• Network Traffic Analysis with Zeek: From Deployment to Threat Detection

• Sysmon and Windows Event Forwarding: Enterprise-Grade

View all
#Banking4 articles

• FBI Warns of ATM Jackpotting Surge as Losses Top $20

• RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

• River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

View all
#Threat Actors4 articles

• Scattered Lapsus$ ShinyHunters Alliance Hits 100+

• Exposed Fuel Tank Gauges Under Attack in the US

• Klue OAuth Breach Linked to 'Icarus' Salesforce Data Theft Attacks

View all
#Fintech4 articles

• Fintech Giant Figure Technology Confirms Breach: Nearly 1

• Cash App Owner to Pay $45 Million Over Lax Security Allegations

• Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

View all
#CrowdStrike4 articles

• CrowdStrike 2026 Threat Report: eCrime Breakout Time Falls

• CrowdStrike Dismantles Glassworm Botnet Targeting Open-Source Supply Chain

• GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

View all
#Cloudflare4 articles

• Cloudflare 2026 Threat Report: 230 Billion Daily Threats as

• Cloudflare BGP Routing Error Cascades Across AWS, X, and More

• CVE-2026-11325: Cloudflare pages-action GitHub Actions RCE

View all
#PhaaS4 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• FBI Dismantles Massive AI-Powered Chinese Phishing-as-a-Service Operation

• Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

View all
#Spain4 articles

• Spanish-Ukrainian Police Bust Gambling Ring That Exploited

• Spain Dismantles Major $4.7M Manga Piracy Platform, Arrests

• Zara Data Breach Exposed Personal Information of 197,000

View all
#Data Theft4 articles

• ShinyHunters Claims Mass Data Theft From 400 Firms via Salesforce Aura

• New BlackFile Extortion Group Linked to Surge of Vishing

• Colorado Governor Commutes Prison Sentence for Election

View all
#GlassWorm4 articles

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

• GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison

• Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach

View all
#Solana4 articles

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

• Crypto Platform Drift Suspends Services After Hundreds of Millions Stolen

• Drift Crypto Platform Confirms $280 Million Stolen as

View all
#Streaming4 articles

• Crunchyroll Probes Breach After Hacker Claims to Steal 6.8M

• Anti-Piracy Coalition Takes Down AnimePlay App with 5

• Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming

View all
#Unauthorized Access4 articles

• Mazda Discloses Security Breach Exposing Employee and Partner Data

• CVE-2026-25199: Apache CloudStack Proxmox Extension Allows

• UniFi OS Improper Access Control — Unauthorized System

View all
#NetScaler4 articles

• Citrix Urges Admins to Patch NetScaler Flaws as Soon as

• Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active

• Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks

View all
#CVE-2026-30554 articles

• Citrix Urges Admins to Patch NetScaler Flaws as Soon as

• Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active

• Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks

View all
#European Commission4 articles

• European Commission Confirms Data Breach After Europa.eu

• CERT-EU: European Commission Hack Exposes Data of 30 EU

• EU Cyber Agency Attributes Major Data Breach to TeamPCP

View all
#TrueConf4 articles

• Hackers Exploit TrueConf Zero-Day to Push Malicious

• PhantomCore Exploits TrueConf Vulnerabilities to Breach

• Head Mare Hacktivists Breach TrueConf to Trojanize Client Installers with PhantomCore Backdoors

View all
#File Transfer4 articles

• New Progress ShareFile Flaws Can Be Chained in Pre-Auth RCE

• CISA: Hackers Now Exploit SolarWinds Serv-U Flaw to Crash Servers

• CVE-2026-14958: IBM Aspera Faspex 5 Shell Injection Enables RCE

View all
#Software Security4 articles

• The State of Trusted Open Source Report: Key Findings for 2025

• Build Application Firewalls Aim to Stop the Next Supply

• How Software Development's Speed Obsession Enabled TeamPCP's Chaos Crusade

View all
#DPRK4 articles

• $285 Million Drift Hack Traced to Six-Month DPRK Social

• Drift $280M Crypto Theft Linked to 6-Month In-Person DPRK

• Amazon Links Debug, Chalk NPM Supply Chain Attacks to North Korean Hackers

View all
#Redis4 articles

• 36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

• Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

• Kimi K3 AI Agents Discovered Redis Zero-Days and Built RCE Exploits in Under 90 Minutes

View all
#PostgreSQL4 articles

• 36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

• Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites

• Critical RCE in Veeam Backup & Replication — Backup Viewer

View all
#Penetration Testing4 articles

• Black Hat USA 2026: What to Expect from the Year''s Biggest

• Nmap Scanning Techniques for Security Professionals

• OSINT Reconnaissance Methodology for Security Professionals

View all
#REvil4 articles

• Germany Doxes "UNKN," Head of RU Ransomware Gangs REvil

• BKA Identifies REvil Leaders Behind 130 German Ransomware

• German Authorities Identify REvil and GandCrab Ransomware

View all
#US Government4 articles

• Trump Budget Proposal Would Cut Hundreds of Millions More

• Commerce Setting Up New AI Export Regime to Push Adoption

• OpenAI Previews GPT-5.6 Sol Under Government-Gated Rollout with Stronger Cyber Safeguards

View all
#Unpatched4 articles

• Disgruntled Researcher Leaks BlueHammer Windows Zero-Day

• Windows BitLocker Zero-Day Gives Access to Protected

• Windows Zero-Days Expose BitLocker Bypasses and CTFMON

View all
#Storm-11754 articles

• Microsoft Links Storm-1175 to Medusa Ransomware Zero-Day

• China-Linked Storm-1175 Chains Zero-Days for High-Velocity

• Storm-1175 Deploys Medusa Ransomware at 'High Velocity'

View all
#NVIDIA4 articles

• GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables

• NVIDIA Confirms GeForce NOW Data Breach Affecting Armenian

• Microsoft, Tech Companies Throw Weight Behind Spread of Open-Source AI

View all
#Snowflake4 articles

• Snowflake Customers Hit in Data Theft Attacks After SaaS

• Canadian Pleads Guilty to Snowflake Cloud Data-Theft Attacks

• Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

View all
#PDF4 articles

• Adobe Reader Zero-Day Exploited via Malicious PDFs Since

• Hackers Exploiting Acrobat Reader Zero-Day Flaw Since

• Adobe Patches Actively Exploited Zero-Day That Lingered for Months

View all
#Business Email Compromise4 articles

• Cybercriminals Target Accountants to Drain Russian Firms'

• ARToken PhaaS Exposes EvilTokens' Microsoft 365 Phishing Toolkit with AI-Powered BEC

• Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

View all
#Detection4 articles

• Your Next Breach Will Look Like Business as Usual

• How to Detect and Block ClickFix Attacks

• Runtime Security Monitoring with Falco: Detect Container

View all
#EDR Bypass4 articles

• Payouts King Ransomware Uses QEMU Virtual Machines to Bypass Endpoint Security

• Making Vulnerable Drivers Exploitable Without Hardware: The

• GodDamn Ransomware Uses PoisonX Kernel Driver to Neutralize Endpoint Security

View all
#Microsoft Teams4 articles

• Microsoft Teams Right-Click Paste Broken by Edge Update Bug

• Threat Actor Uses Microsoft Teams to Deploy New 'Snow'

• KongTuke Hackers Now Use Microsoft Teams for Corporate

View all
#AppSec4 articles

• Analysis of 216M Security Findings Shows a 4x Increase in Critical Risk (2026 Report)

• Software Is Now Written at the Speed of Thought. Security Isn't.

• What Changes When AI Writes Your Code: Supply Chain Security in the Age of LLMs

View all
#Business Continuity4 articles

• The Backup Myth That Is Putting Businesses at Risk

• BridgePay Payment Gateway Knocked Offline by Ransomware

• What Rural Alberta Businesses Get Wrong About Ransomware

View all
#BeyondTrust4 articles

• Surge in Bomgar RMM Exploitation Demonstrates Supply Chain

• BeyondTrust Remote Support and PRA Critical RCE Under

• BeyondTrust Remote Support Pre-Authentication RCE Under

View all
#RMM4 articles

• Surge in Bomgar RMM Exploitation Demonstrates Supply Chain

• WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

• NinjaOne Scripting: PowerShell Automation Library

View all
#Checkmarx4 articles

• Malicious KICS Docker Images and VS Code Extensions Hit

• Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain

• Checkmarx Confirms GitHub Repository Data Posted on Dark

View all
#Hospitality4 articles

• New BlackFile Extortion Group Linked to Surge of Vishing

• ClickFix Campaign Targets European Hotels with Fake

• CVE-2026-14688: SQL Injection in itsourcecode Hotel Management Admin Login

View all
#Threat Actor4 articles

• New BlackFile Extortion Group Linked to Surge of Vishing

• TeamPCP Hackers Advertise Mistral AI Source Code Repos for Sale

• ShinyHunters Claims Brinks Home Breach, Threatens to Leak Stolen Data

View all
#Copilot4 articles

• Microsoft Now Lets Admins Uninstall Copilot on Enterprise

• SearchLeak: New Attack Turned Microsoft 365 Copilot into 1-Click Data Theft Tool

• Microsoft Announces Major Security Features for Copilot

View all
#Tor4 articles

• Firefox Vulnerability Allows Tor User Fingerprinting Across

• CryptoBandits Malware Doubles as a Backdoor, Abuses Tor for Stealthy C2

• Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

View all
#FTC4 articles

• FTC: Americans Lost Over $2.1 Billion to Social Media Scams

• Here's How the FTC Plans to Enforce the Take It Down Act

• FTC Warns of Record $3.5 Billion in Losses to Imposter Scams in 2025

View all
#Medtronic4 articles

• Medtronic Confirms Breach After Hackers Claim 9 Million

• Medtronic Hack Confirmed After ShinyHunters Threatens Data

• Medtronic Notifies Customers Impacted by ShinyHunters Data Breach

View all
#Canvas4 articles

• Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

• Canvas Breach Disrupts Schools & Colleges Nationwide

• Multiple Universities Forced to Reschedule Final Exams

View all
#OFAC4 articles

• In Other News: Scattered Spider Member Arrested, SOC

• The U.S. Sanctions Nobitex Crypto Exchange Used by Ransomware

• US Treasury Sanctions 1VPNS: The VPN Service Favored by Ransomware Groups

View all
#Malvertising4 articles

• Hackers Abuse Google Ads and Claude.ai Chats to Push Mac

• New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

• SourTrade: Malicious Sites Use JavaScript to Assemble Malware Directly in Browser Memory

View all
#2FA4 articles

• Google Detects First AI-Generated Zero-Day Exploit in the Wild

• Hackers Used AI to Develop First Known Zero-Day 2FA Bypass

• Malicious Chrome Extension 'CL Suite' Steals Meta Business

View all
#Mini Shai-Hulud4 articles

• OpenAI Confirms Security Breach in TanStack Supply Chain

• TanStack Supply Chain Attack Hits Two OpenAI Employee

• TeamPCP Hackers Advertise Mistral AI Source Code Repos for Sale

View all
#Financial Security4 articles

• More Than $10 Million Stolen from Crypto Platform THORChain

• Why Chargebacks Are Just One Piece of the Fraud Puzzle

• SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

View all
#Shai-Hulud4 articles

• TeamPCP Ups the Game, Releases Shai-Hulud Worm's Source Code

• Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

• GitHub Confirms Being Hacked by TeamPCP, Says Customer Data

View all
#Defense4 articles

• The Boring Stuff Is Dangerous Now

• New U.S. Cyber Force Would Cost Up to $11 Billion to Start, Commission Says

• Cyber Force Not Included in Senate Defense Policy Roadmap

View all
#Election Security4 articles

• Colorado Governor Commutes Prison Sentence for Election

• Can Laws Stop Deepfakes? South Korea Aims to Find Out

• ODNI Taps Officials to Coordinate Response to Foreign

View all
#Acquisitions4 articles

• SecurityScorecard Acquires Driftnet to Boost Third-Party

• SailPoint to Acquire Entro in Reported $200 Million Deal

• Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions

View all
#Governance4 articles

• 5 Steps to Managing Shadow AI Tools Without Slowing Down

• Geordie Raises $30 Million for AI Security and Governance Platform

• Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

View all
#Drupal4 articles

• Drupal Patches Highly Critical Vulnerability Exposing

• Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites

• Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

View all
#Chromium4 articles

• Google Accidentally Exposed Details of Unfixed Chromium Flaw

• AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android

• CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

View all
#Arrest4 articles

• ''First VPN'' Cybercrime Service Disrupted, Administrator

• Alleged Kimwolf Botmaster ''Dort'' Arrested, Charged in U.S. and Canada

• Canadian Man Arrested and Charged for Running KimWolf DDoS

View all
#Laravel4 articles

• Laravel Lang Packages Hijacked to Deploy

• Laravel-Lang PHP Packages Compromised to Deliver

• CVE-2025-54068: Laravel Livewire Code Injection

View all
#Gitea4 articles

• Gitea Vulnerability Exposes Private Container Images without Authentication

• Hackers Exploit Critical Auth Bypass in Official Gitea Docker Image

• CVE-2026-20896: Gitea Docker Image Authentication Bypass

View all
#23andMe4 articles

• California AG Sues 23andMe Over 2023 Breach Exposing Genetic Health Data

• 23andMe $47 Million Settlement Approved for 7 Million Breach Victims

• 23andMe to Pay $18 Million in New Genetics Data Breach Settlement

View all
#GlobalProtect4 articles

• Palo Alto GlobalProtect VPN Auth Bypass Flaw Now Exploited in Attacks

• PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

• Critical Palo Alto VPN Bug Now Exploited by Qilin Ransomware Gang

View all
#Dashlane4 articles

• Dashlane Password Manager Users Locked Out by Brute Force Attacks

• Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

• Dashlane Discloses Brute-Force Attack: Encrypted Vaults of Fewer Than 20 Users Downloaded

View all
#Brute Force4 articles

• Dashlane Password Manager Users Locked Out by Brute Force Attacks

• Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

• Dashlane Discloses Brute-Force Attack: Encrypted Vaults of Fewer Than 20 Users Downloaded

View all
#Pakistan4 articles

• Pakistan-Linked SideCopy APT Targets Afghanistan Finance Ministry with Xeno RAT

• China and India Ran Separate Spying Campaigns Against the Same Pakistani Police Force

• China and India-Linked Hackers Both Targeted the Same Pakistani Police Force

View all
#Cyber Policy4 articles

• New U.S. Cyber Force Would Cost Up to $11 Billion to Start, Commission Says

• Cyber Force Not Included in Senate Defense Policy Roadmap

• Launch of UK's National Cyber Action Plan Delayed Amid Labour Leadership Crisis

View all
#FFmpeg4 articles

• AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

• FFmpeg Fixes PixelSmash Flaw in Widely Used Video Decoder

• FFmpeg PixelSmash: CVE-2026-8461 Enables RCE via Crafted Video Files Across Thousands of Apps

View all
#SolarWinds4 articles

• CISA: Hackers Now Exploit SolarWinds Serv-U Flaw to Crash Servers

• CVE-2026-28302: SolarWinds Serv-U IDOR Leads to Root RCE

• CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption (DoS)

View all
#PeopleSoft4 articles

• Oracle Mitigates PeopleSoft Zero-Day Exploited in Data Theft Attacks

• ShinyHunters Uses Oracle Zero-Day to Rampage Higher Education

• Google Confirms ShinyHunters Exploited Oracle PeopleSoft Zero-Day CVE-2026-35273

View all
#Enterprise Software4 articles

• Cyberattack on Russian Tech Firm Astral Disrupts Business and Government Services for a Week

• CVE-2022-4995: Weaver E-cology 9.0 Unauthenticated File Upload Enables Webshell RCE

• CVE-2025-62319: Critical SQL Injection in HCL Unica (CVSS

View all
#INC Ransomware4 articles

• INC Ransomware Thrives by Mastering the Basics

• Inc Ransomware Exploits Chained SonicWall SMA Zero-Days for Root Access

• INC Ransomware Emerges as Dominant Threat Actor Exploiting SonicWall SMA 1000 Flaws

View all
#Code Execution4 articles

• Microsoft Fixes AutoGen Studio Flaw That Enabled Code Execution

• CVE-2018-25320: ACL Analytics Arbitrary Code Execution via EXECUTE Function

• CVE-2026-32999: Comet Backup Server Code Execution via Signing Module

View all
#StealC4 articles

• Amadey and StealC Malware Networks Disrupted, 27 Million Stolen Credentials Recovered

• Microsoft and Europol Dismantle Three Cybercrime-as-a-Service Operations

• FakeGit Campaign Uses 7,600 GitHub Repos to Push SmartLoader Malware

View all
#Industry News4 articles

• In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs

• Nebulock Raises $25 Million for AI-Native Contextual Security

• Guten Tag, Bonjour, Hola: Dark Reading Launches European Cyber Defenders Hub

View all
#Threat Hunting4 articles

• Nebulock Raises $25 Million for AI-Native Contextual Security

• SentinelOne Threat Hunting Recipes: Practical Deep

• Velociraptor DFIR: Endpoint Forensics and Incident Response

View all
#Embedded Security4 articles

• 7 Unpatched Flaws Disclosed in FatFs Filesystem Used in Millions of Embedded Devices

• Flipper Zero Firmware Development Continues With Community Help

• Six U-Boot Flaws Could Enable Stealthy Firmware Attacks on Embedded Devices

View all
#ai-security4 articles

• Chinese LLMs Broaden the Gap Between Attackers & Defenders

• Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

• Venture Firm Team8 Secures Additional $365 Million

View all
#GitLab4 articles

• Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

• CISA Adds Four Critical Vulnerabilities to KEV Catalog

• CVE-2026-10087: GitLab EE Stored XSS via Developer Role

View all
#Data Security4 articles

• Cyera Acquiring Oasis Security in $1 Billion Deal

• Varonis Launches Agent IBAC to Keep AI Agents Within Their Intended Boundaries

• Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

View all
#Credential Exposure4 articles

• OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

• CVE-2025-36568: Dell PowerProtect Data Domain BoostFS

• CVE-2026-19264: Critical Path Traversal in Postiz Exposes JWT Secrets and DB Credentials

View all
#Remote Access4 articles

• Microsoft Teams Vishing Attacks Lead to Chaos Ransomware Deployment

• CVE-2026-3564: ConnectWise ScreenConnect Auth Bypass via Server Cryptographic Material

• FortiGate SSL VPN Setup: Secure Remote Access Configuration

View all
#Apache Tomcat4 articles

• CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

• CVE-2016-20026: ZKTeco ZKBioSecurity 3.0 Hardcoded Tomcat

• CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

View all
#Authentication4 articles

• Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

• CVE-2026-13332: Masteriyo LMS Allows Unauthenticated Force-Logout of Any User

• CVE-2026-14364: TrueBooker WordPress Plugin Account Takeover via Password Reset Bypass

View all
#zero-trust4 articles

• When Credentials Are No Longer Enough: Device Trust in the AI Era

• HashiCorp Vault: Centralized Secrets Management for Modern

• OpenSSH Hardening with Certificate-Based Authentication

View all
#SCADA4 articles

• Cyberattacks on Critical Infrastructure Double in Q1 2026

• CVE-2026-12183: Critical Auth Bypass in Gas Station Automation System

• CVE-2026-16462: PROCON-WEB SCADA Unauthenticated SQL Injection (CVSS 9.8)

View all
#Coolify4 articles

• Coolify CVE-2026-34037: CVSS 9.9 IDOR Enables Cross-Team Resource Takeover

• Coolify CVE-2026-34047: Terminal WebSocket Authorization Bypass (CVSS 9.9)

• Coolify CVE-2026-34048: Low-Privilege Terminal Escalation via WebSocket (CVSS 9.9)

View all
#CSRF4 articles

• CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability

• CVE-2026-2611: MLflow 3.9.0 Improper Origin Validation

• CVE-2026-3589: WooCommerce CSRF Flaw Allows Unauthenticated

View all
#CPAN4 articles

• CVE-2011-10043: Perl Module::Load Arbitrary Module Injection Resurfaces

• CVE-2025-15618: Perl Payment Module Uses Insecure

• CVE-2026-8507: Crypt::OpenSSL::PKCS12 Heap OOB Write — CVSS

View all
#Cross-Site Scripting4 articles

• CVE-2015-20118: Stored XSS in RealtyScript 4.0.2 Admin

• CVE-2025-61311: Reflected XSS in docuForm Managed Print

• CVE-2026-10087: GitLab EE Stored XSS via Developer Role

View all
#Stack Overflow4 articles

• CVE-2016-20049: JAD Java Decompiler Stack-Based Buffer

• CVE-2017-20225: TiEmu TI Calculator Emulator Stack Buffer

• CVE-2017-20230: Perl Storable Stack Overflow — CVSS 10.0

View all
#CWE-1214 articles

• CVE-2016-20049: JAD Java Decompiler Stack-Based Buffer

• CVE-2017-20225: TiEmu TI Calculator Emulator Stack Buffer

• CVE-2026-10187: Totolink N300RH Stack Buffer Overflow in WiFi Config

View all
#AJAX4 articles

• CVE-2021-47932: WordPress TheCartPress 1.5.3.6 Privilege

• CVE-2026-12923: YouTube Showcase WordPress Plugin Arbitrary Function Call

• CVE-2026-13423: Streamit WordPress Theme Allows Unauthenticated Arbitrary PHP Function Execution

View all
#CWE-2694 articles

• CVE-2021-47932: WordPress TheCartPress 1.5.3.6 Privilege

• CVE-2026-25770: Wazuh Privilege Escalation to Root via Cluster Protocol File Write

• CVE-2026-32922: OpenClaw Privilege Escalation via Token

View all
#CVSS 9.94 articles

• CVE-2025-14771: ABB T-MAC Plus Critical File & Directory Exposure (CVSS 9.9)

• CVE-2026-14450: MaaS API Auth Bypass via Forged HTTP Headers

• CVE-2026-18948: Feast Feature Store RCE via Unsafe Deserialization

View all
#Arbitrary File Write4 articles

• CVE-2025-15036: MLflow Path Traversal in Archive Extraction

• CVE-2026-14289: FacturaONE WooCommerce Plugin Allows Unauthenticated File Write

• CVE-2026-15265: Tenable Agent Path Traversal — Arbitrary File Write & RCE (CVSS 9.1)

View all
#PowerProtect4 articles

• CVE-2025-36568: Dell PowerProtect Data Domain BoostFS

• CVE-2026-49814: Dell PowerProtect Data Domain OS Command Injection

• CVE-2026-53481: Dell PowerProtect Data Domain Path Traversal — CVSS 9.8

View all
#Education Software4 articles

• CVE-2025-67403: Critical SQL Injection in CASAP Enrollment System update_class.php

• CVE-2025-67404: Critical SQL Injection in CASAP Enrollment System save_stud.php

• CVE-2026-11334: SQL Injection in College Management System

View all
#SSO4 articles

• CVE-2026-11374: ManageEngine SSO Ticket Prediction Enables Unauthenticated Account Takeover

• CVE-2026-15013: WordPress SAML SSO Plugin — Algorithm Confusion Auth Bypass

• Multi-Stack Docker Infrastructure with Traefik and Authentik

View all
#Unauthenticated Access4 articles

• CVE-2026-11841: AppEngine Fileaccess Unauthenticated Filesystem R/W (CVSS 9.4)

• CVE-2026-28766: Gardyn Smart Garden API Exposes All User

• CVE-2026-34162: FastGPT Unauthenticated HTTP Proxy Enables

View all
#Embedded Device4 articles

• CVE-2026-12485: GeoVision GV-I/O Box 4E UDP Stack Overflow (IP Address Field)

• CVE-2026-12486: GeoVision GV-I/O Box 4E OS Command Injection via libNetSetObj.so

• CVE-2026-12846: GeoVision GV-I/O Box 4E UDP Stack Overflow (Net Mask Field)

View all
#SSTI4 articles

• CVE-2026-14453: Critical SSTI to RCE in Centreon Open Tickets (CVSS 9.6)

• GlassFish Gadget Handler Expression Language RCE

• CVE-2026-44377: CubeCart Authenticated SSTI via Smarty

View all
#CWE-3474 articles

• CVE-2026-15013: WordPress SAML SSO Plugin — Algorithm Confusion Auth Bypass

• CVE-2026-31946: Critical JWT Signature Verification Bypass

• CVE-2026-3564: ConnectWise ScreenConnect Auth Bypass via Server Cryptographic Material

View all
#CWE-6394 articles

• CVE-2026-2346: Critical Authorization Bypass in Menulux Mobile App

• Critical Session Hijacking via Auth Bypass in Akilli

• CVE-2026-25197: IDOR Flaw Lets Authenticated Users Access

View all
#SiYuan4 articles

• CVE-2026-33669: SiYuan Unauthenticated Document Content

• CVE-2026-33670: SiYuan readDir Path Traversal Notebook

• CVE-2026-40259 — SiYuan Knowledge Management Authorization

View all
#Knowledge Management4 articles

• CVE-2026-33669: SiYuan Unauthenticated Document Content

• CVE-2026-33670: SiYuan readDir Path Traversal Notebook

• CVE-2026-40259 — SiYuan Knowledge Management Authorization

View all
#vm24 articles

• CVE-2026-47131: vm2 Sandbox Escape via Buffer Prototype Hijack (CVSS 10.0)

• CVE-2026-47137: vm2 Sandbox Escape via Strict Equality require Bypass (CVSS 10.0)

• CVE-2026-47140: vm2 Sandbox Escape via Incomplete Builtin Denylist (CVSS 10.0)

View all
#Avi Load Balancer4 articles

• CVE-2026-47865: Critical Authentication Bypass in VMware Avi Load Balancer

• CVE-2026-47866: Authorization Bypass in VMware Avi Load Balancer

• CVE-2026-47867: Remote Code Execution via Code Injection in VMware Avi Load Balancer

View all
#APSB26-684 articles

• CVE-2026-48276: Adobe ColdFusion Critical File Upload RCE (CVSS 10.0)

• CVE-2026-48277: Adobe ColdFusion Critical Input Validation RCE (CVSS 10.0)

• CVE-2026-48281: Adobe ColdFusion Input Validation RCE Zero-Day (CVSS 10.0)

View all
#OT4 articles

• OpENer CIP Integer Overflow — CVE-2026-51536

• OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537

• OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538

View all
#File Write4 articles

• CVE-2026-56260: Crawl4AI Arbitrary File Write in Docker API

• CVE-2026-56445: DICOM qrscp Path Traversal Enables Arbitrary File Write

• CVE-2026-57898: Eclipse BaSyx Unauthenticated File Write in IIoT SDK (CVSS 9.0)

View all
#Thunderbird4 articles

• CVE-2026-5731: Firefox and Thunderbird Critical Memory

• CVE-2026-6748: Critical Uninitialized Memory Flaw in Firefox and Thunderbird Web Codecs

• CVE-2026-6785: Memory Safety Bugs in Firefox and Thunderbird Enable Arbitrary Code Execution

View all
#Network Devices4 articles

• CVE-2026-71948: D-Link DWR-M961 Command Injection via formDebugDiagnosticRun

• CVE-2026-71949: D-Link DWR-M961 Command Injection via formUSSDSetup

• CVE-2026-71950: D-Link DWR-M961 Command Injection via formSmsManage

View all
#MSI4 articles

• MSI Radix AXE6600 Critical Command Injection in WPS Interface (CVE-2026-71983)

• MSI Radix AXE6600 Critical Command Injection in URL Filter Function (CVE-2026-71984)

• MSI Radix AXE6600 Critical Command Injection in Access Control Function (CVE-2026-71985)

View all
#blue-team4 articles

• Network Traffic Analysis with Zeek: From Deployment to Threat Detection

• Sysmon and Windows Event Forwarding: Enterprise-Grade

• Deploy OpenCanary to Catch Attackers Inside Your Network

View all
#DFIR4 articles

• Velociraptor DFIR Setup, Hunts, and Forensic Collection

• Osquery Endpoint Visibility & Threat Hunting

• Incident Response Playbook: Ransomware

View all
#Conditional Access4 articles

• The Microsoft 365 Security Baseline Every Small Business Should Have

• Conditional Access Policies: Zero Trust with Entra ID

• Microsoft 365 Security and Compliance Configuration Guide

View all
#XDR4 articles

• How to Deploy Wazuh SIEM/XDR for Unified Security Monitoring

• Microsoft Defender for Endpoint: Configuration and Hardening

• Building a Wazuh XDR + SIEM Homelab

View all
#Intune4 articles

• Microsoft Defender for Endpoint: Configuration and Hardening

• Intune Device Enrollment: Windows Autopilot Setup

• Microsoft 365 Security Baseline Implementation

View all
#device-control4 articles

• SentinelOne Control vs Complete Feature Comparison

• SentinelOne Device Control Configuration

• SentinelOne MSP Client Onboarding

View all
#Verizon3 articles

• Senator Demands AT&T, Verizon CEOs Testify Over Salt

• Verizon DBIR 2026: Healthcare Fends Off Rising Social

• What the 2026 DBIR Confirms: Attacks Are Living in the Browser

View all
#Antitrust3 articles

• Google's $32 Billion Wiz Acquisition Clears Final Hurdle as

• Google Loses Final Appeal to Overturn €4.1 Billion EU Antitrust Fine

• EU Fines Google $1 Billion for Search and App Store DMA Violations

View all
#DHS3 articles

• IRS Shares Tax Data of 1.28 Million Individuals with DHS

• CISA Loses 62% of Workforce as DHS Shutdown Guts America's

• DHS Confirms Hackers Breached HSIN Federal Info-Sharing Platform

View all
#Trends3 articles

• Ransomware in 2026: Data-Only Extortion Replaces Encryption

• Cybersecurity Predictions 2026: The Hype We Can Ignore and the Real Risks

• Ransomware Attacks Surge 49% Year-Over-Year: BlackFog 2026

View all
#Lapsus$3 articles

• Scattered Lapsus$ ShinyHunters Alliance Hits 100+

• Mercor Confirms Security Incident Tied to LiteLLM Supply

• Blast Radius of TeamPCP Attacks Expands Amid Hacker

View all
#Aviation3 articles

• Japan Airlines Confirms Data Breach Affecting 28,000

• Malaysia Airlines Listed by Qilin Ransomware Group

• Iranian APT Targets Aviation, Software Companies With

View all
#Biometrics3 articles

• Persona Source Code Leak Exposes Hidden Biometric

• UK to Require Government ID or Face Scan Before Creating Social Media Accounts

• The Future of Age Verification: Your Face Never Leaves Your Device

View all
#Age Verification3 articles

• Persona Source Code Leak Exposes Hidden Biometric

• UK to Require Government ID or Face Scan Before Creating Social Media Accounts

• The Future of Age Verification: Your Face Never Leaves Your Device

View all
#Italy3 articles

• Pro-Russian Hacktivists Launch Sustained Cyber Campaign

• Italian Regulator Fines National Postal Service Orgs $15

• Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming

View all
#Semiconductor3 articles

• Japanese Semiconductor Giant Advantest Hit by Ransomware

• Analog Devices Discloses Data Breach, Says Operations Unaffected

• Semiconductor Chip Titan Analog Devices Reports Data Breach

View all
#Amazon3 articles

• AI-Armed Amateur Hacker Compromises 600+ FortiGate

• Amazon Fined $2.25M by FTC for Blocking Identity Theft Victims' Evidence

• Amazon Alexa+ Goes GA After Tens of Millions Join Beta

View all
#Logistics3 articles

• Diesel Vortex: Russian Cybercrime Ring Steals 1,649

• FBI Links Cybercriminals to Sharp Surge in Cargo Theft

• OnTrac Notifies Customers of Data Breach After Network Hack

View all
#Israel3 articles

• Iran Plunged Into Digital Darkness: Internet Drops to 4% in Cyberattack

• Operation Epic Fury Triggers Unprecedented Cyber Escalation

• Researchers Detect ZionSiphon Malware Targeting Israeli

View all
#ALPHV3 articles

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

• US Ransomware Negotiators Get 4 Years in Prison Over

• Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

View all
#Guilty Plea3 articles

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

• Former DigitalMint Ransomware Negotiator Pleads Guilty to $75.3M Extortion Scheme

• Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

View all
#Defense Strategy3 articles

• The Zero-Day Scramble Is Avoidable: Why Attack Surface

• 73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation

• The Race to Field Military Autonomy Is On — Can Trusted Information Infrastructure Keep Pace?

View all
#Bug3 articles

• Windows 11 February Update Breaks C:\ Drive Access on Samsung PCs

• Microsoft Teams Right-Click Paste Broken by Edge Update Bug

• Microsoft June 2026 Updates Break Recycle Bin Confirmation Prompts on All Windows Versions

View all
#Cybercrime Takedown3 articles

• Operation Synergia III: Police Sinkhole 45,000 IPs in Global Cybercrime Crackdown

• Police Shut Down Reboot of Crimenetwork Marketplace, Arrest

• FBI and Google Dismantle 'Outsider Enterprise' Phishing-as-a-Service Platform

View all
#MDM3 articles

• Stryker Cyberattack Wiped Tens of Thousands of Devices — No

• Microsoft Now Lets Admins Uninstall Copilot on Enterprise

• CVE-2026-49185: FieldX MDM ADB Topic Command Injection via Runtime.exec()

View all
#CVE-2026-24413 articles

• Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach

• Google Patches First Chrome Zero-Day of 2026: CVE-2026-2441

• Google Chrome Use-After-Free Zero-Day Under Active

View all
#Financial Services3 articles

• Marquis Ransomware Breach: 672K People Exposed as Attack

• DORA and Operational Resilience: Credential Management as a

• American Lending Center Data Breach Affects 123,000

View all
#Akira3 articles

• Marquis Ransomware Breach: 672K People Exposed as Attack

• Akira Hackers Disable EDR with Safe Mode, Steal Data but Fail to Encrypt

• Ransomware Attacks Surge in Early 2026 with 26 Claims in One Day

View all
#Hardware Security3 articles

• Eclypsium Raises $25 Million to Expand Device Supply Chain

• GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables

• New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

View all
#AI Infrastructure3 articles

• Eclypsium Raises $25 Million to Expand Device Supply Chain

• Adani Pledges $100 Billion for Renewable-Powered AI Data

• CVE-2026-24207: NVIDIA Triton Inference Server Auth Bypass

View all
#Trivy3 articles

• Trivy Security Scanner GitHub Actions Breached — 75 Tags

• Cisco Source Code Stolen in Trivy-Linked Dev Environment

• European Commission Confirms Data Breach Linked to Trivy

View all
#DarkSword3 articles

• DarkSword GitHub Leak Threatens to Turn Elite iPhone

• TA446 Deploys DarkSword iOS Exploit Kit in Targeted

• Apple Expands iOS 18 Updates to More iPhones to Block

View all
#Web Skimmer3 articles

• PolyShell Attacks Target 56% of All Vulnerable Magento

• WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

• Polymarket Customers Lose $3 Million in Supply-Chain Attack

View all
#Hacktivist3 articles

• Pro-Ukraine Hacker Group Bearlyfy Targets Russian Companies

• PhantomCore Exploits TrueConf Vulnerabilities to Breach

• Head Mare Hacktivists Breach TrueConf to Trojanize Client Installers with PhantomCore Backdoors

View all
#Steganography3 articles

• Backdoored Telnyx PyPI Package Pushes Malware Hidden in WAV

• TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides

• APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine

View all
#CVE-2025-535213 articles

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• F5 BIG-IP Vulnerability Reclassified from DoS to RCE Under

• Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE

View all
#Spear-Phishing3 articles

• TA446 Deploys DarkSword iOS Exploit Kit in Targeted

• APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine

• Fake Microsoft Security Alerts Used to Deploy North Korean NarwhalRAT Malware

View all
#NCII3 articles

• Dutch Court Threatens xAI with Fines Over Grok's

• UK Government Threatens Tech Bosses With Jail Time Over AI

• NY Man Charged After Harassing College Student with AI-Generated Nude Images

View all
#FCC3 articles

• FCC Bans Import of Foreign-Made Consumer Routers Over

• FCC Proposes $4.5 Million Fine for Voice Provider Hosting

• FCC Proposes New Rule to Further Crack Down on Illegal

View all
#California3 articles

• Foster City Declares State of Emergency After Ransomware

• GM Agrees to $12.75M California Settlement Over Sale of Drivers' Data

• California AG Sues 23andMe Over 2023 Breach Exposing Genetic Health Data

View all
#UNC10693 articles

• Axios NPM Package Breached in North Korean Supply Chain

• Google Attributes Axios npm Supply Chain Attack to North

• North Korean Hackers Use Fake Zoom Meeting to Target Crypto

View all
#Hack3 articles

• Crypto Platform Drift Suspends Services After Hundreds of Millions Stolen

• $3 Million Reportedly Stolen in Polymarket Hack

• Truebit Protocol Hit by $26.5 Million DeFi Hack via Smart

View all
#Crypto Heist3 articles

• Drift Crypto Platform Confirms $280 Million Stolen as

• Drift Loses $280 Million as Hackers Seize Security Council

• KelpDAO Suffers $290 Million Heist Tied to Lazarus Hackers

View all
#Drift Protocol3 articles

• Drift Crypto Platform Confirms $280 Million Stolen as

• Drift Loses $280 Million as Hackers Seize Security Council

• 'It Reads Like a Spy Novel': $280M Drift Theft Linked to North Korean Fake Companies

View all
#Governance Attack3 articles

• Drift Crypto Platform Confirms $280 Million Stolen as

• Drift Loses $280 Million as Hackers Seize Security Council

• Attackers Vote Themselves $20 Million in BONK Cryptocurrency via Governance Attack

View all
#Shadowserver3 articles

• Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE

• Actively Exploited Apache ActiveMQ Flaw Impacts 6,400

• GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

View all
#Chainguard3 articles

• The State of Trusted Open Source Report: Key Findings for 2025

• Chainguard Unveils Factory 2.0 to Automate Hardening the Software Supply Chain

• Growing Up The Hard Way: Open Source Security's Painful Maturation

View all
#SBOM3 articles

• The State of Trusted Open Source Report: Key Findings for 2025

• What Changes When AI Writes Your Code: Supply Chain Security in the Age of LLMs

• Growing Up The Hard Way: Open Source Security's Painful Maturation

View all
#Texas3 articles

• 250,000 Affected by Data Breach at Nacogdoches Memorial

• Texas Govt Data Breach Exposes Over 3 Million Driver's Licenses

• Texas Parks & Wildlife Data Breach Affects 3 Million Individuals

View all
#Germany3 articles

• Die Linke German Political Party Confirms Data Stolen by Qilin Ransomware

• BKA Identifies REvil Leaders Behind 130 German Ransomware

• Police Shut Down Reboot of Crimenetwork Marketplace, Arrest

View all
#Zendesk3 articles

• Hims & Hers Warns of Data Breach After Zendesk Support

• 300,000+ Passport Numbers Leaked in December Eurail Data

• Hims & Hers Breach Exposes the Most Sensitive Kinds of Patient PHI

View all
#Black Hat3 articles

• Black Hat USA 2026: What to Expect from the Year''s Biggest

• AI-Assisted HTTP Terminator Finds Novel Desync Techniques and Apache Zero-Day

• New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

View all
#GandCrab3 articles

• Germany Doxes "UNKN," Head of RU Ransomware Gangs REvil

• BKA Identifies REvil Leaders Behind 130 German Ransomware

• German Authorities Identify REvil and GandCrab Ransomware

View all
#DNS Hijacking3 articles

• Authorities Disrupt APT28 Router DNS Hijacks Targeting

• Russia's Forest Blizzard Harvests Logins via SOHO Router

• CubePilot Drone Software Dev Hit by DNS Hijacking to Intercept Traffic

View all
#Medusa3 articles

• China-Linked Storm-1175 Chains Zero-Days for High-Velocity

• Storm-1175 Deploys Medusa Ransomware at 'High Velocity'

• New StormEncryptor Ransomware Used by Former Medusa Affiliate

View all
#IC33 articles

• FBI: Americans Lost a Record $21 Billion to Cybercrime Last

• FBI: Cybercrime Losses Neared $21 Billion in 2025

• FBI: Americans Lost Over $388 Million to Crypto ATM Scams

View all
#Investment Fraud3 articles

• FBI: Americans Lost a Record $21 Billion to Cybercrime Last

• FBI: Cybercrime Losses Neared $21 Billion in 2025

• US Charges Two New Yorkers for Laundering $43 Million in Pig Butchering Investment Fraud

View all
#Ninja Forms3 articles

• Hackers Exploit Critical Flaw in Ninja Forms WordPress

• CVE-2026-65048: Ninja Forms Unauthenticated Stored XSS via Repeatable Fieldset

• CVE-2026-65049: Ninja Forms Multisite Flaw Enables Network-Wide Data Deletion

View all
#IAM3 articles

• The Hidden Cost of Recurring Credential Incidents

• Gartner Identifies the Top 6 Cybersecurity Trends Reshaping

• Microsoft Entra PIM: Configuring Just-in-Time Admin Access

View all
#cyber insurance3 articles

• The Hidden Cost of Recurring Credential Incidents

• Why Every Business Needs Cyber Insurance in 2026

• The 10 Controls Every Canadian Cyber-Insurance Carrier Asks About in 2026

View all
#Acrobat Reader3 articles

• Adobe Reader Zero-Day Exploited via Malicious PDFs Since

• Hackers Exploiting Acrobat Reader Zero-Day Flaw Since

• CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution

View all
#Online Safety Act3 articles

• UK Government Threatens Tech Bosses With Jail Time Over AI

• UK to Require Government ID or Face Scan Before Creating Social Media Accounts

• UK Brings AI Chatbots Under the Online Safety Act

View all
#Mirai3 articles

• Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack

• New Mirai Campaign Exploits RCE Flaw in End-of-Life D-Link

• New Evooo1Bot Linux Botnet Turns Routers Into Traffic Relay Nodes

View all
#Water Security3 articles

• Researchers Detect ZionSiphon Malware Targeting Israeli

• Iran, Russia, and China Target Water Systems for Sabotage

• Senate Democrats Introduce Water Cyber Shield Act to Fund $300M Annual Water System Cybersecurity

View all
#Performance3 articles

• Microsoft Teams to Get Efficiency Mode for Low-Resource PCs

• Claude Fable Relaunch Disappoints Users With Nerfed Performance

• FortiGate Performance Optimization: A Tuning Guide for Throughput

View all
#Piracy3 articles

• Spain Dismantles Major $4.7M Manga Piracy Platform, Arrests

• Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming

• Police Dismantles 9 Crime Groups in Illegal Streaming Crackdown

View all
#CVE-2026-38443 articles

• Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

• Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

• CVE-2026-3844 — Breeze Cache WordPress Plugin

View all
#ADT3 articles

• ADT Confirms Data Breach After ShinyHunters Leak Threat

• ADT Says Customer Data Stolen in Cyber Intrusion

• Home Security Giant ADT Data Breach Affects 5.5 Million

View all
#Bitwarden3 articles

• Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain

• ETH Zurich Finds 25 Password Recovery Attacks Against

• Self-Hosted Password Manager with Vaultwarden

View all
#JFrog3 articles

• Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain

• FFmpeg PixelSmash: CVE-2026-8461 Enables RCE via Crafted Video Files Across Thousands of Apps

• JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

View all
#Exchange Server3 articles

• Microsoft Patch Tuesday, March 2026 Edition

• Microsoft Patches Exploited Exchange Server Vulnerability CVE-2026-42897

• Microsoft Exchange Server SSRF to RCE Chain Actively

View all
#Consumer Security3 articles

• FTC: Americans Lost Over $2.1 Billion to Social Media Scams

• Chick-fil-A Discloses Data Breach After Credential Stuffing Attacks

• Chick-fil-A Data Breach Affects More Than 13,000 Customers

View all
#Have I Been Pwned3 articles

• Home Security Giant ADT Data Breach Affects 5.5 Million

• Zara Data Breach Exposed Personal Information of 197,000

• Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

View all
#Zero-Click3 articles

• Incomplete Windows Patch Opens Door to Zero-Click Attacks

• Apple Sends New Threat Notification Alerts Over Mercenary Spyware Attacks

• Mail2Shell: Zero-Click RCE in FreeScout Helpdesk

View all
#Medical Devices3 articles

• Medtronic Confirms Breach After Hackers Claim 9 Million

• Medtronic Hack Confirmed After ShinyHunters Threatens Data

• Medical Device Maker Notifies Nearly 4 Million Patients of Data Breach

View all
#Crypto Fraud3 articles

• Money Launderer Linked to $230M Crypto Heist Gets 70 Months

• European Police Dismantles €50 Million Crypto Investment

• US & China Partner on Scam Center Takedown in Dubai

View all
#Robotics3 articles

• Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

• As Global Powers Explore Humanoid Robots, Cyber-Risk Looms

• CVE-2026-8153: Universal Robots PolyScope OS Command

View all
#ConnectWise3 articles

• CISA Adds Actively Exploited ConnectWise and Windows Flaws

• CVE-2024-1708: ConnectWise ScreenConnect Path Traversal

• CVE-2026-3564: ConnectWise ScreenConnect Auth Bypass via Server Cryptographic Material

View all
#OpenEMR3 articles

• AI Finds 38 Security Flaws in Electronic Health Record

• CVE-2026-32238: Critical Command Injection in OpenEMR

• CVE-2026-39932: Critical RCE in OpenEMR via PHP Payload Injection

View all
#Child Safety3 articles

• European Commission Accuses Meta of Breaching Child Safety

• Canadian Man Gets 33 Years for Using Social Media to Coerce US Children

• UK Brings AI Chatbots Under the Online Safety Act

View all
#Go3 articles

• Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

• CVE-2026-15704: Critical Auth Bypass in Eclipse BaSyx Go Components

• CVE-2026-35392: Critical Path Traversal in goshs Go HTTP

View all
#Instructure3 articles

• Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

• Multiple Universities Forced to Reschedule Final Exams

• Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65 TB Canvas Leak

View all
#Trellix3 articles

• Trellix Confirms Source Code Breach With Unauthorized

• Trellix Source Code Breach Claimed by RansomHouse Hackers

• Trellix Source Code Breach Highlights Growing Supply Chain

View all
#RansomHouse3 articles

• Trellix Source Code Breach Claimed by RansomHouse Hackers

• Trellix Source Code Breach Highlights Growing Supply Chain

• RansomHouse Freezes Japan's Food Supply: Nichirei Logistics Cyberattack Disrupts KFC and Thousands of Clients

View all
#WHM3 articles

• cPanel & WHM Release Fixes for Three New Vulnerabilities

• CVE-2026-41940: WebPros cPanel & WHM and WP2 Missing

• CVE-2026-47365: WordPress Toolkit Argument Injection in cPanel & WHM

View all
#CCPA3 articles

• GM to Pay Over $12 Million in Largest-Ever CCPA Fine Over

• GM to Pay Over $12 Million in California Privacy Settlement

• GM Agrees to $12.75M California Settlement Over Sale of Drivers' Data

View all
#Higher Education3 articles

• Multiple Universities Forced to Reschedule Final Exams

• ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities

• ShinyHunters Uses Oracle Zero-Day to Rampage Higher Education

View all
#Windows Security3 articles

• Why Changing Passwords Doesn't End an Active Directory

• Configuring Windows LAPS: Automated Local Admin Password

• Group Policy Security Hardening for Windows Environments

View all
#Venture Capital3 articles

• Exaforce Raises $125 Million for Agentic SOC Platform

• Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation

• AegisAI Raises $36 Million for AI-Powered Email Security

View all
#FortiSandbox3 articles

• Fortinet Warns of Critical RCE Flaws in FortiSandbox and FortiAuthenticator

• Attackers Hit Pair of Critical Fortinet Vulnerabilities the Vendor Disclosed in April

• CISA Orders Immediate Patching of Actively Exploited Fortinet FortiSandbox Flaws

View all
#Pharmaceutical3 articles

• West Pharmaceutical Services Hit by Disruptive Ransomware

• West Pharmaceutical Warns of Ransomware Attack Impacting

• Pharma Giant Novo Nordisk Discloses Breach of Clinical Trials Data

View all
#Foxconn3 articles

• Foxconn Confirms Cyberattack Claimed by Nitrogen Ransomware

• Foxconn Confirms North American Factories Hit by Cyberattack

• Foxconn Attack Highlights Manufacturing's Cyber Crisis

View all
#Corporate Security3 articles

• KongTuke Hackers Now Use Microsoft Teams for Corporate

• Kodak Admits Data Breach After ShinyHunters Hack Claims

• Accenture Confirms Data Breach After Hacker Claims Source Code Theft

View all
#Exchange3 articles

• Microsoft Warns of Exchange Zero-Day Flaw Exploited in Attacks

• Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

• Microsoft Exchange Zero-Day Under Attack, No Patch Available

View all
#Source Code Theft3 articles

• TeamPCP Hackers Advertise Mistral AI Source Code Repos for Sale

• Grafana Says Stolen GitHub Token Let Hackers Steal Codebase

• Accenture Confirms Data Breach After Hacker Claims Source Code Theft

View all
#Responsible Disclosure3 articles

• Microsoft Rejects Critical Azure Vulnerability Report, No

• Microsoft Says Zero-Day Public Releases Are 'Never Justifiable' as Researcher Threatens More Drops

• Microsoft's Zero-Day Legal Threats Spark Backlash

View all
#7-Eleven3 articles

• 7-Eleven Data Breach Confirmed After ShinyHunters Ransom

• 7-Eleven Confirms Data Breach Claimed by the ShinyHunters

• 185,000 Likely Impacted by 7-Eleven Data Breach

View all
#Bug Bounty3 articles

• Hackers Earn $1,298,250 for 47 Zero-Days at Pwn2Own Berlin

• Bug Bounty Research Triggers ServiceNow Security Alert

• In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

View all
#Industry Analysis3 articles

• Looking Back, Looking Forward: Two Decades of Cybersecurity

• Cybersecurity Evolution: From Perimeter Defense to AI-Native Security

• Ransomware Costs Projected to Hit $74 Billion in 2026, 30%

View all
#App Store3 articles

• Apple Blocked Over $11 Billion in App Store Fraud in 6 Years

• Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention

• Apple Sued Over Fake App Store Crypto Wallet That Stole $1.8M in Bitcoin

View all
#CMS Security3 articles

• Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites

• CVE-2026-39397: PayloadCMS Puck Plugin Access Control Bypass

• Critical Authentication Bypass in WordPress Temporary Login

View all
#Bulletproof Hosting3 articles

• Netherlands Seizes 800 Servers of Hosting Firm Enabling

• Dutch Raid Fails to Dent Russian Bulletproof Host THE.Hosting

• US Charges Three Russians for Operating Bulletproof Hosting Behind $62M Ransomware Campaign

View all
#BYOVD3 articles

• Making Vulnerable Drivers Exploitable Without Hardware: The

• 'GodDamn' Ransomware Uses BYOVD Technique to Kill Security Software at US Companies

• Reynolds Ransomware Embeds BYOVD Driver to Disable EDR

View all
#Social Media3 articles

• Canadian Man Gets 33 Years for Using Social Media to Coerce US Children

• New Mexico Judge Orders Meta to Pay $567 Million in Kids Online Safety Case

• CVE-2026-19264: Critical Path Traversal in Postiz Exposes JWT Secrets and DB Credentials

View all
#Consumer Privacy3 articles

• Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People

• Charter Communications Data Breach Affects 4.9 Million Accounts

• Man Sent to Prison for Selling Data of 7 Million Elderly Americans

View all
#VPN Security3 articles

• Palo Alto GlobalProtect VPN Auth Bypass Flaw Now Exploited in Attacks

• PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

• CISA Warns Fortinet Users to Secure Devices After FortiBleed Credential Leak

View all
#Frontier AI3 articles

• Frontier AI Reinforces the Future of Modern Cyber Defense

• OpenAI Previews GPT-5.6 Sol Under Government-Gated Rollout with Stronger Cyber Safeguards

• OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

View all
#Domain Controller3 articles

• Critical Windows Netlogon RCE Flaw Now Exploited in Attacks

• Domain Controller Hardening: Securing Active Directory

• Active Directory Health Check: Comprehensive Diagnostic

View all
#Residential Proxy3 articles

• Dutch Police Dismantle Massive 17-Million-Device Botnet

• Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices

• NetNut Proxy Network Disrupted, 2 Million Infected Devices Cut Off

View all
#EDR Evasion3 articles

• AI-Built Ransomware Toolkit Automates EDR Evasion and AD Discovery

• The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

• Reynolds Ransomware Embeds BYOVD Driver to Disable EDR

View all
#VoIP3 articles

• Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches

• CVE-2026-45538: OpenSIPS Stack Buffer Overflow via Oversized SIP Header

• Critical Grandstream VoIP Vulnerability Allows

View all
#Risk Assessment3 articles

• Security of 100 AI Agents Tested and Ranked – What You Need to Know

• Ransomware Costs Projected to Hit $74 Billion in 2026, 30%

• Vulnerability Management Checklist

View all
#Smart TV3 articles

• Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI

• NetNut Proxy Network Disrupted, 2 Million Infected Devices Cut Off

• LG to Ban Residential Proxies from Smart TV Apps

View all
#Serv-U3 articles

• CISA: Hackers Now Exploit SolarWinds Serv-U Flaw to Crash Servers

• CVE-2026-28302: SolarWinds Serv-U IDOR Leads to Root RCE

• CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption (DoS)

View all
#JetBrains3 articles

• Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

• CVE-2026-59792: JetBrains IntelliJ IDEA Remote Code Execution via Path Traversal

• CVE-2026-63077: JetBrains TeamCity Deserialization RCE Added to CISA KEV

View all
#SocGholish3 articles

• 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

• Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

• Microsoft and Europol Dismantle Three Cybercrime-as-a-Service Operations

View all
#Industrial Security3 articles

• Accenture to Acquire Majority Stake in Dragos, runZero, and NetRise in $4.1 Billion OT Cybersecurity Push

• Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

• CVE-2026-8153: Universal Robots PolyScope OS Command

View all
#AI Governance3 articles

• French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation

• Microsoft, Tech Companies Throw Weight Behind Spread of Open-Source AI

• India Hosts Global AI Impact Summit — 20 World Leaders and Tech CEOs

View all
#Wallet Security3 articles

• USB Worm Spreads Crypto-Stealing Malware via Windows Shortcut Files

• Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

• CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

View all
#FortiBleed3 articles

• FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist

• Russian Initial Access Broker Behind FortiBleed Campaign

• FortiBleed Credential-Theft Campaign Linked to Lynx Ransomware Group

View all
#Pig Butchering3 articles

• Chinese DCloud Uni-App Framework Powers 200,000+ Global Investment Scam Sites

• US Charges Two New Yorkers for Laundering $43 Million in Pig Butchering Investment Fraud

• SE Asian Cybercriminal Syndicates Become a Global Power

View all
#Browser Extension3 articles

• Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

• Google and Microsoft Pull ModHeader After Hidden Tracker Found in 1.6M-Install Extension

• Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

View all
#Insurance3 articles

• NAIC Says Only Public Data Stolen in ShinyHunters PeopleSoft Breach

• Insurance Giant Aflac Discloses Data Breach After Subsidiary Hack

• CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

View all
#Cursor IDE3 articles

• Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

• 2-Click Cursor Exploit Enables Dev Environment Takeover

• CVE-2026-63093: Cursor for Windows Binary Planting Allows RCE via Malicious Git Repository

View all
#India3 articles

• China and India Ran Separate Spying Campaigns Against the Same Pakistani Police Force

• Adani Pledges $100 Billion for Renewable-Powered AI Data

• India Hosts Global AI Impact Summit — 20 World Leaders and Tech CEOs

View all
#Reconnaissance3 articles

• Ghost Accounts Abuse GitHub API in Mass Recon Campaign

• Nmap Scanning Techniques for Security Professionals

• OSINT Reconnaissance Methodology for Security Professionals

View all
#CVE-2026-154093 articles

• SonicWall Warns of SMA1000 Flaws Exploited in Zero-Day Attacks, Patch Now

• SonicWall Warns of Two Zero-Day Exploits Targeting SMA1000 — Patch Immediately

• Prolific Ransomware Group Behind SonicWall Zero-Day Attacks

View all
#CVE-2026-154103 articles

• SonicWall Warns of SMA1000 Flaws Exploited in Zero-Day Attacks, Patch Now

• SonicWall Warns of Two Zero-Day Exploits Targeting SMA1000 — Patch Immediately

• Prolific Ransomware Group Behind SonicWall Zero-Day Attacks

View all
#OpenSSL3 articles

• HollowByte: 11-Byte Payload Triggers Memory Bloat DoS on OpenSSL Servers

• HollowByte: 11-Byte Payload Triggers OpenSSL Server Memory Exhaustion

• CVE-2026-8507: Crypt::OpenSSL::PKCS12 Heap OOB Write — CVSS

View all
#Machine Learning Security3 articles

• JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware

• CVE-2025-15379: MLflow Command Injection in Model Serving

• CVE-2026-0596: MLflow Command Injection via Unsanitized

View all
#Arista3 articles

• Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks

• CVE-2024-27890: Arista EOS OpenConfig gNMI Authorization Bypass (CVSS 9.6)

• CVE-2024-27892: Arista EOS OpenConfig gNMI Set Bypass (CVSS 9.6)

View all
#Autonomous Attacks3 articles

• Chinese Threat Actor Uses DeepSeek and Hermes Agent to Launch Fully Autonomous Cyberattacks

• Hacker Uses DeepSeek AI to Autonomously Attack Vulnerable Servers

• Chinese Hacker Uses DeepSeek via Telegram to Launch Fully Autonomous Cyberattacks

View all
#Payment Security3 articles

• Interpol Leverages Global System to Curtail Fraud Payments

• CVE-2020-37168: Systempay Weak Crypto Allows Payment

• CVE-2026-11964: WordPress User Registration Plugin PayPal Webhook Bypass

View all
#N-able3 articles

• CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

• China-Linked Storm-1175 Deploys StormEncryptor Ransomware via Critical N-central Flaw

• CVE-2026-18577: N-able N-central Authentication Bypass and Account Takeover

View all
#Webmail3 articles

• New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

• Hackers Breach Govt Webmail While Running Parallel Crypto Fraud

• CISA Adds Two Actively Exploited Roundcube Webmail Flaws to KEV

View all
#Business Intelligence3 articles

• Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

• Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

• Critical RCE in Hitachi Vantara Pentaho via Unrestricted

View all
#phishing3 articles

• When Credentials Are No Longer Enough: Device Trust in the AI Era

• Valve Notifies Steam Hardware Customers of CEVA Logistics Data Breach

• FBI: Hackers Using Social Engineering to Breach Accounts and Steal Explicit Content

View all
#MITM3 articles

• Signal Adds Automatic Key Verification to Thwart Man-in-the-Middle Attacks

• CVE-2026-48144: Apache Thrift c_glib TLS Certificate Host Mismatch (CVSS 9.1)

• Apache HttpComponents TLS Hostname Verification Bypass

View all
#open-source3 articles

• Who Vets AI's Code? The Scale Challenge Facing Open Source Ingestion

• Building a SOAR Platform with Shuffle in Your Homelab

• OWASP DefectDojo: Self-Hosted Vulnerability Management Platform

View all
#Statistics3 articles

• 2026 Vulnerability Forecast: Up to 117,000 CVEs Expected

• Ransomware Costs Projected to Hit $74 Billion in 2026, 30%

• Ransomware Attacks Surge 49% Year-Over-Year: BlackFog 2026

View all
#M3653 articles

• Microsoft Hit by Back-to-Back Outages: M365 Admin Center

• Microsoft Announces Major Security Features for Copilot

• The Microsoft 365 Security Baseline Every Small Business Should Have

View all
#Notepad++3 articles

• Notepad++ Supply Chain Attack Attributed to China-Linked

• CVE-2026-52884: Notepad++ Trusted Directory Bypass via Path Traversal (CVSS 7.8)

• Lotus Blossom APT Compromises Notepad++ Updates to Deploy

View all
#Google TAG3 articles

• Russian-Linked CANFAIL Malware Targets Ukrainian Defense

• Apple Patches Actively Exploited iOS Zero-Day Used in Targeted Attacks

• Apple Patches Actively Exploited Zero-Day in dyld

View all
#CVE-2026-17313 articles

• BeyondTrust Remote Support and PRA Critical RCE Under

• BeyondTrust Remote Support Pre-Authentication RCE Under

• BeyondTrust Zero-Day Allows Unauthenticated Command

View all
#ZKTeco3 articles

• CVE-2016-20024: ZKTeco ZKTime.Net Insecure File Permissions

• CVE-2016-20026: ZKTeco ZKBioSecurity 3.0 Hardcoded Tomcat

• CVE-2016-20030: ZKTeco ZKBioSecurity 3.0 Username

View all
#CWE-4343 articles

• CVE-2016-20052: Snews CMS 1.7 Unrestricted File Upload

• CVE-2021-47933: WordPress MStore API 2.0.6 Arbitrary File

• CVE-2021-47936: OpenCATS 0.9.4 Unauthenticated RCE via PHP

View all
#Tenda3 articles

• CVE-2024-51311: Critical Stack Overflow in Tenda TX9 Router Firmware

• Tenda A15 UploadCfg Stack Buffer Overflow (CVE-2026-4567)

• CVE-2026-51380: Tenda AC10 v3 Buffer Overflow Enables DoS and Remote Code Execution

View all
#SOHO3 articles

• CVE-2024-51311: Critical Stack Overflow in Tenda TX9 Router Firmware

• CVE-2026-31027: TOTOlink A3600R Buffer Overflow in setAppEasyWizardConfig

• CVE-2026-7154: Totolink A8000RU OS Command Injection via CGI Handler

View all
#CORS3 articles

• CVE-2025-34291: Langflow Origin Validation Error

• Critical CORS + Path Traversal in TinaCMS CLI Dev Server

• CVE-2026-61736: LightRAG Critical CORS Credential Bypass (CVSS 9.3)

View all
#Data Domain3 articles

• CVE-2025-36568: Dell PowerProtect Data Domain BoostFS

• CVE-2026-53481: Dell PowerProtect Data Domain Path Traversal — CVSS 9.8

• CVE-2026-53483: Dell PowerProtect Data Domain Authentication Bypass — CVSS 9.8

View all
#Apache Airflow3 articles

• CVE-2025-57735: Apache Airflow JWT Token Not Invalidated on Logout

• CVE-2026-33264: Apache Airflow Scheduler RCE via DAG Deserialization

• CVE-2026-58065: Apache Airflow Git Provider Disables SSH Host Key Verification

View all
#Remote Exploitation3 articles

• CVE-2026-10184: SourceCodester Hospital Records SQL Injection via Delete

• CVE-2026-10185: SourceCodester Hospital Records SQL Injection via Save

• CVE-2026-10236: Improper Authorization in SourceCodester Water Billing Management System

View all
#WebSphere3 articles

• CVE-2026-11707: IBM WebSphere Application Server Admin Console XSS (CVSS 9.3)

• CVE-2026-14446: IBM WebSphere Admin Console Privilege Escalation

• CVE-2026-14512: IBM WebSphere Pre-Auth Deserialization Allows RCE

View all
#Wordfence3 articles

• CVE-2026-12415: WordPress Invoice Generator Privilege Escalation (CVSS 9.8)

• ARVE WordPress Plugin Backdoor Grants Instant Admin Access to ~20,000 Sites

• CVE-2026-8095: WordPress Frontend File Manager Plugin Allows Arbitrary File Deletion

View all
#Improper Authentication3 articles

• CVE-2026-14205: WP Events Manager Plugin Allows Fraudulent Paid Event Bookings via Payment Bypass

• CVE-2026-53471: migration-planner JWT Source ID Claim Not Validated in Agent API

• KodExplorer fileGet Auth Bypass — Unauthenticated Remote

View all
#File Deletion3 articles

• CVE-2026-14487: WordPress Simple Coherent Form Plugin — Critical Unauthenticated File Deletion

• CVE-2026-3141: WordPress FormGent Plugin Unauthorized File Deletion (CVSS 9.1)

• CVE-2026-8095: WordPress Frontend File Manager Plugin Allows Arbitrary File Deletion

View all
#Missing Authentication3 articles

• CVE-2026-14622: Missing Authentication in Restaurant Website PHP/MySQL AJAX Endpoint

• CVE-2026-4312: DrangSoft GCB/FCB Audit Software Missing

• CVE-2026-6577: DjangoBlog Missing Authentication in OwnTracks logtracks Endpoint

View all
#CodeIgniter3 articles

• CVE-2026-14635: Unrestricted File Upload RCE in CodeIgniter Ecommerce Bootstrap

• CVE-2026-14637: PHP Deserialization RCE in CodeIgniter Ecommerce Bootstrap Shopping Cart

• CVE-2026-48062: CodeIgniter File Upload Validation Bypass (CVSS 9.8)

View all
#MySQL3 articles

• CVE-2026-14641: Remote SQL Injection in SourceCodester Class and Exam Timetabling System

• CVE-2026-14642: Remote SQL Injection in SourceCodester Timetabling System edit_class2.php

• CVE-2026-48188: OTRS Database Layer SQL Injection — Authentication Bypass

View all
#Admin Panel3 articles

• CVE-2026-14653: SQL Injection in Shopping Cart Men's Product Delete Endpoint

• CVE-2026-14654: SQL Injection in Shopping Cart Girls Product Delete Endpoint

• CVE-2026-9525: SQL Injection in itsourcecode Electronic

View all
#Arbitrary File Upload3 articles

• CVE-2026-14894: WordPress Super Forms Plugin Critical Arbitrary File Upload

• CVE-2026-15282: WordPress Instant Appointment Plugin Critical File Upload

• CVE-2026-6885: Borg SPM 2007 Arbitrary File Upload Enables

View all
#Server-Side Request Forgery3 articles

• CVE-2026-19516: SSRF in mcp-grafana Allows Arbitrary Outbound Requests

• scalar/astro Proxy Endpoint Unauthenticated SSRF

• Typecho 1.3.0 Pingback SSRF via X-Pingback Manipulation

View all
#LibRaw3 articles

• CVE-2026-20889: LibRaw x3f_thumb_loader Heap Buffer

• CVE-2026-20911: LibRaw HuffTable::initval Heap Buffer

• CVE-2026-21413: LibRaw lossless_jpeg_load_raw Heap Buffer

View all
#RAW Image3 articles

• CVE-2026-20889: LibRaw x3f_thumb_loader Heap Buffer

• CVE-2026-20911: LibRaw HuffTable::initval Heap Buffer

• CVE-2026-21413: LibRaw lossless_jpeg_load_raw Heap Buffer

View all
#Reverse Proxy3 articles

• CVE-2026-20896: Gitea Docker Image Authentication Bypass

• CVE-2026-35051: Traefik ForwardAuth Authentication Bypass

• Multi-Stack Docker Infrastructure with Traefik and Authentik

View all
#Domain User3 articles

• Veeam Backup & Replication Auth RCE — CVE-2026-21666

• Veeam Backup & Replication 2nd Auth RCE — CVE-2026-21667

• Critical RCE in Veeam Backup & Replication — Third Domain

View all
#CWE-2843 articles

• CVE-2026-21994: Critical Unauthenticated RCE in Oracle Edge

• CVE-2026-25199: Apache CloudStack Proxmox Extension Allows

• CVE-2026-34162: FastGPT Unauthenticated HTTP Proxy Enables

View all
#Spinnaker3 articles

• CVE-2026-25534: Spinnaker SSRF via URL Validation Bypass

• CVE-2026-32604: Spinnaker Clouddriver Remote Code Execution

• CVE-2026-32613: Spinnaker Echo Spring Expression Language

View all
#CWE-223 articles

• CVE-2026-25770: Wazuh Privilege Escalation to Root via Cluster Protocol File Write

• CVE-2026-33670: SiYuan readDir Path Traversal Notebook

• CVE-2026-7302: SGLang Unauthenticated Path Traversal

View all
#Template Injection3 articles

• CVE-2026-26026: GLPI Template Injection Enables

• CVE-2026-41258: OpenMRS Velocity Template Injection Enables

• CVE-2026-9558: Critical SSTI in Mautic Enables Authenticated RCE

View all
#Out-of-Bounds3 articles

• CVE-2026-28815: swift-crypto X-Wing HPKE Out-of-Bounds Read

• CVE-2026-4149: Sonos Era 300 Unauthenticated RCE via SMB

• OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537

View all
#ZITADEL3 articles

• CVE-2026-29067: ZITADEL Password Reset Poisoned by Host Header Injection

• ZITADEL Critical XSS in SAML Endpoint Enables 1-Click

• CVE-2026-29192: ZITADEL Stored XSS via Default Redirect URI

View all
#Network Device3 articles

• CVE-2026-31027: TOTOlink A3600R Buffer Overflow in setAppEasyWizardConfig

• CVE-2026-32956: Critical Heap Buffer Overflow in silex

• CVE-2026-7136: Totolink A8000RU OS Command Injection via setDmzCfg

View all
#Unbound3 articles

• CVE-2026-33278 — NLnet Labs Unbound DNSSEC Validator RCE

• CVE-2026-42960 — NLnet Labs Unbound DNS Cache Poisoning

• Pi-hole v6 + Unbound: Network-Wide DNS Sinkhole with Recursive Resolution

View all
#Canonical3 articles

• CVE-2026-34177: Canonical LXD Incomplete VM Restriction

• CVE-2026-34178: Canonical LXD Backup Import Path

• CVE-2026-5412: Juju Controller Facade Allows Low-Privilege

View all
#MiTM3 articles

• CVE-2026-35560: Amazon Athena ODBC Driver Fails Certificate

• CVE-2026-50208: TLS Bypass and Hard-Coded DES Keys Enable MITM Attacks

• CVE-2026-58065: Apache Airflow Git Provider Disables SSH Host Key Verification

View all
#Apache Camel3 articles

• CVE-2026-40047: Apache Camel Docling Argument Injection Enables OS Command Execution

• CVE-2026-40453: Apache Camel Header Filter Case-Variant

• CVE-2026-40860: Apache Camel JMS Unsafe ObjectMessage

View all
#Image Processing3 articles

• CVE-2026-40492: SAIL XWD Codec Heap Buffer Overflow (CVSS

• CVE-2026-40493: SAIL PSD Codec Buffer Overflow via channels

• CVE-2026-40494: SAIL TGA Codec RLE Decoder Asymmetric

View all
#SAIL3 articles

• CVE-2026-40492: SAIL XWD Codec Heap Buffer Overflow (CVSS

• CVE-2026-40493: SAIL PSD Codec Buffer Overflow via channels

• CVE-2026-40494: SAIL TGA Codec RLE Decoder Asymmetric

View all
#Hard-Coded Credentials3 articles

• Dell ECS and ObjectScale: Hard-Coded Credentials

• CVE-2026-49191: M3WebServer Hard-Coded API Keys Exposed via Error Pages

• CVE-2026-50208: TLS Bypass and Hard-Coded DES Keys Enable MITM Attacks

View all
#Server Administration3 articles

• CVE-2026-41228 — Froxlor Path Traversal via def_language

• CVE-2026-41229 — Froxlor PHP Code Injection via MySQL

• SSH Hardening Best Practices

View all
#Apache MINA3 articles

• CVE-2026-41635: Apache MINA Class Allowlist Bypass Enables

• Apache MINA Incomplete Deserialization Patch Leaves 2.1.X

• CVE-2026-42779: Critical Apache MINA Deserialization Class

View all
#authentik3 articles

• CVE-2026-42849: authentik Critical XSS in AutosubmitStage (CVSS 9.3)

• CVE-2026-49448: authentik Source Stage Authentication Bypass (CVSS 9.8)

• Multi-Stack Docker Infrastructure with Traefik and Authentik

View all
#CWE-3063 articles

• CVE-2026-4312: DrangSoft GCB/FCB Audit Software Missing

• CVE-2026-61514: Puwell IP Camera Authentication Bypass

• CVE-2026-6577: DjangoBlog Missing Authentication in OwnTracks logtracks Endpoint

View all
#GitOps3 articles

• CVE-2026-43824: Argo CD ServerSideDiff Exposes Cleartext

• Kubernetes Secrets Management with External Secrets Operator

• Kubernetes Homelab Cluster with K3s

View all
#Injection3 articles

• CVE-2026-45688: Rocket.Chat CAS Login MongoDB Operator Injection (CVSS 9.1)

• CVE-2026-45689: Rocket.Chat OAuth Token Hijack via MongoDB Operator Injection (CVSS 9.1)

• CVE-2026-56699: Critical NDJSON Injection in Wazuh Manager (CVSS 10.0)

View all
#OpENer3 articles

• OpENer CIP Integer Overflow — CVE-2026-51536

• OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537

• OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538

View all
#EtherNet/IP3 articles

• OpENer CIP Integer Overflow — CVE-2026-51536

• OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537

• OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538

View all
#CIP3 articles

• OpENer CIP Integer Overflow — CVE-2026-51536

• OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537

• OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538

View all
#migration-planner3 articles

• CVE-2026-53469: migration-planner Missing Authorization on Bulk Delete

• CVE-2026-53470: migration-planner IDOR Exposes Cross-Tenant S3 Pre-Signed URLs

• CVE-2026-53471: migration-planner JWT Source ID Claim Not Validated in Agent API

View all
#ERP3 articles

• CVE-2026-59500: Priority Portal Generator Authentication Bypass — CVSS 10.0

• CVE-2026-59504: Priority Portal Generator Client-Side Security Bypass (CVSS 9.1)

• Business Central Docker Containers: Development Environment

View all
#End of Life Software3 articles

• CVE-2026-6885: Borg SPM 2007 Arbitrary File Upload Enables

• CVE-2026-6886: Borg SPM 2007 Authentication Bypass Allows

• CVE-2026-6887: Borg SPM 2007 SQL Injection Exposes Full

View all
#FortiOS3 articles

• Fortinet FortiOS SSL VPN Heap Overflow Enables Pre-Auth RCE

• FortiGate Performance Optimization: A Tuning Guide for Throughput

• FortiGate Security Hardening: Best Practices for Enterprise

View all
#vulnerability-scanning3 articles

• Container Security Scanning with Trivy: Images, IaC, and CI/CD

• OpenVAS / Greenbone: Open-Source Vulnerability Scanning

• Nuclei Vulnerability Scanning Pipeline

View all
#IDS3 articles

• Suricata IDS/IPS Deployment: From Install to Active Threat

• Network Monitoring Basics: Detect Threats Before They Spread

• Network Traffic Analysis with Zeek and Suricata

View all
#intrusion-detection3 articles

• Suricata IDS/IPS Deployment: From Install to Active Threat

• Deploy OpenCanary to Catch Attackers Inside Your Network

• AIDE File Integrity Monitoring: Detect Unauthorized Changes on Linux

View all
#intrusion-prevention3 articles

• CrowdSec: Deploy a Community-Powered Intrusion Prevention System

• Fail2ban: Automated Brute Force Protection for Linux Servers

• Build a Collaborative IPS with CrowdSec

View all
#Logging3 articles

• Sysmon and Windows Event Forwarding: Enterprise-Grade

• FortiAnalyzer Log Forwarding and Compliance Reports

• Build a Centralized Log Management System with Loki and Grafana

View all
#endpoint-security3 articles

• Sysmon and Windows Event Forwarding: Enterprise-Grade

• Velociraptor DFIR Setup, Hunts, and Forensic Collection

• Osquery Endpoint Visibility & Threat Hunting

View all
#Security Baseline3 articles

• The Microsoft 365 Security Baseline Every Small Business Should Have

• Security Baseline Hardening: CIS Controls Implementation

• Microsoft 365 Security Baseline Implementation

View all
#linux3 articles

• WireGuard VPN: Secure Remote Access for IT Professionals

• AIDE File Integrity Monitoring: Detect Unauthorized Changes on Linux

• OpenSSH Hardening with Certificate-Based Authentication

View all
#SOAR3 articles

• How to Configure Microsoft Sentinel Analytics Rules

• Building a SOAR Platform with Shuffle in Your Homelab

• Azure Sentinel SIEM Implementation

View all

All Tags

#Vulnerability(476)
#CVE(390)
#RCE(310)
#Data Breach(294)
#Supply Chain(268)
#Ransomware(228)
#Cybercrime(214)
#Zero-Day(192)
#Malware(184)
#NVD(168)
#BleepingComputer(162)
#Threat Intelligence(158)
#Critical(156)
#WordPress(149)
#AI Security(145)
#Microsoft(133)
#SQL Injection(119)
#Security Updates(118)
#The Hacker News(107)
#Privilege Escalation(99)
#Cloud Security(93)
#Windows(91)
#Web Security(89)
#Authentication Bypass(88)
#Remote Code Execution(82)
#Law Enforcement(81)
#APT(76)
#Security(74)
#Russia(68)
#Phishing(67)
#PHP(67)
#Nation-State(64)
#AI(64)
#npm(64)
#CISA KEV(64)
#Healthcare(63)
#Critical Infrastructure(62)
#Google(57)
#Command Injection(55)
#Privacy(53)
#CISA(53)
#Open Source(50)
#China(49)
#Unauthenticated(49)
#Network Security(48)
#Credential Theft(47)
#Linux(47)
#Social Engineering(46)
#Espionage(45)
#Cryptocurrency(45)
#ShinyHunters(42)
#Patch Tuesday(42)
#Active Exploitation(40)
#GitHub(39)
#sentinelone(39)
#Path Traversal(39)
#automation(39)
#Cisco(38)
#Account Takeover(38)
#edr(38)
#Plugin Vulnerability(38)
#File Upload(37)
#IoT(36)
#Fortinet(34)
#Infostealer(34)
#Router(34)
#Government(33)
#policy(33)
#Fraud(33)
#SourceCodester(33)
#Android(32)
#North Korea(31)
#DevSecOps(31)
#Docker(31)
#CWE-89(31)
#OpenAI(30)
#AWS(30)
#Botnet(30)
#Deserialization(30)
#Anthropic(29)
#threat-hunting(29)
#Incident Response(28)
#TeamPCP(28)
#Apple(27)
#Chrome(27)
#firewall(27)
#ICS(27)
#VPN(27)
#deployment(27)
#detection-rules(27)
#Agentic AI(26)
#Developer Security(26)
#Python(26)
#XSS(26)
#api(26)
#Extortion(25)
#Web Application(25)
#Mobile Security(24)
#Authorization Bypass(24)
#FBI(23)
#macOS(23)
#CVSS 9.8(23)
#DOJ(22)
#ClickFix(22)
#SecurityWeek(22)
#Azure(22)
#Buffer Overflow(22)
#incident-response(22)
#Enterprise Security(21)
#Ukraine(21)
#Browser Security(21)
#CI/CD(20)
#KEV(20)
#WooCommerce(19)
#Homelab(19)
#E-Commerce(18)
#IoT Security(18)
#Code Injection(18)
#OS Command Injection(18)
#Cybersecurity(17)
#Sandbox Escape(17)
#Prompt Injection(17)
#Oracle(17)
#Kubernetes(17)
#Compliance(17)
#SSRF(17)
#OT Security(17)
#SIEM(17)
#Telecom(16)
#DDoS(16)
#Iran(16)
#Takedown(16)
#Identity Security(16)
#Email Security(16)
#CVSS 10(16)
#Java(16)
#forensics(16)
#Perl(16)
#Funding(15)
#OAuth(15)
#GitHub Actions(15)
#PyPI(15)
#Patch Now(15)
#Claude(15)
#D-Link(15)
#Education(14)
#Europol(14)
#Third-Party Risk(14)
#Salesforce(14)
#Firmware(14)
#Patch(14)
#iOS(14)
#DeFi(14)
#Backdoor(14)
#Adobe(14)
#Endpoint Security(14)
#MCP(14)
#SD-WAN(14)
#PowerShell(14)
#API Security(14)
#Insider Threat(13)
#FortiGate(13)
#JavaScript(13)
#Langflow(13)
#Netherlands(13)
#Microsoft 365(13)
#Security Research(13)
#Artificial Intelligence(13)
#Zero Trust(13)
#SonicWall(13)
#VMware(13)
#cPanel(13)
#DNS(13)
#CMS(13)
#Node.js(13)
#Access Control(13)
#CWE-78(13)
#mitre-attack(13)
#PII(12)
#Blockchain(12)
#General(12)
#Cryptography(12)
#Open Source Security(12)
#NGINX(12)
#Active Directory(12)
#TLS(12)
#Totolink(12)
#Dark Web(11)
#Enterprise(11)
#Japan(11)
#Identity Theft(11)
#RaaS(11)
#HIPAA(11)
#ChatGPT(11)
#Weekly Recap(11)
#Startup(11)
#Worm(11)
#The Record(11)
#smb(11)
#authentication(11)
#SOC(11)
#UK(11)
#Memory Corruption(11)
#Ubiquiti(11)
#Joomla(11)
#High(11)
#Hardening(11)
#Actively Exploited(10)
#LLM(10)
#RAT(10)
#Use-After-Free(10)
#Container Security(10)
#SAP(10)
#Ivanti(10)
#TanStack(10)
#Manufacturing(10)
#UniFi(10)
#IBM(10)
#Stored XSS(10)
#Database(10)
#Plugin(10)
#OpenClaw(9)
#Vulnerability Research(9)
#Money Laundering(9)
#Vulnerability Management(9)
#DevOps(9)
#canada(9)
#Data Exfiltration(9)
#France(9)
#Dark Reading(9)
#BEC(9)
#Encryption(9)
#Regulation(9)
#Source Code(9)
#Next.js(9)
#KrebsOnSecurity(9)
#Router Security(9)
#Backup(9)
#SharePoint(9)
#Vercel(9)
#Sentencing(9)
#Hugging Face(9)
#LMS(9)
#Web Server(9)
#DoS(9)
#Exploitation(9)
#Grafana(9)
#Information Disclosure(9)
#Dell(9)
#code-projects(9)
#CVSS 9.1(9)
#APT28(8)
#Infrastructure(8)
#Web Application Security(8)
#Spyware(8)
#n8n(8)
#Veeam(8)
#Automotive(8)
#GDPR(8)
#Plugin Security(8)
#Claude Code(8)
#Physical Security(8)
#Patient Data(8)
#Identity(8)
#Entra ID(8)
#Retail(8)
#SEC Disclosure(8)
#Apache(8)
#Critical Vulnerability(8)
#Red Hat(8)
#Machine Learning(8)
#Unauthenticated RCE(8)
#Networking(8)
#CIS Benchmarks(8)
#Monitoring(8)
#EU(7)
#Financial Crime(7)
#Deepfake(7)
#Surveillance(7)
#Developer Tools(7)
#MFA Bypass(7)
#Samsung(7)
#Cyberattack(7)
#Zimbra(7)
#Qilin(7)
#LiteLLM(7)
#Exploit(7)
#AI Regulation(7)
#Data Protection(7)
#Axios(7)
#Lazarus Group(7)
#Weekly Roundup(7)
#AI Policy(7)
#Windows Server(7)
#Web Hosting(7)
#PAN-OS(7)
#Self-Hosted(7)
#Threat Detection(7)
#AI Safety(7)
#Hardcoded Credentials(7)
#Missing Authorization(7)
#GeoVision(7)
#CWE-94(7)
#Heap Buffer Overflow(7)
#Traefik(7)
#Geopolitics(6)
#DeepSeek(6)
#Europe(6)
#BlackCat(6)
#Workflow Automation(6)
#Federal(6)
#Backup & Replication(6)
#Enterprise Backup(6)
#VS Code(6)
#Windows 11(6)
#Interpol(6)
#Shadow AI(6)
#Citrix(6)
#Magento(6)
#National Security(6)
#WebSocket(6)
#Supply Chain Security(6)
#Southeast Asia(6)
#Bitcoin(6)
#Crypto(6)
#Pre-Auth(6)
#Supply Chain Attack(6)
#CyberScoop(6)
#Credentials(6)
#Risk Management(6)
#Export Controls(6)
#Microsoft Edge(6)
#C2(6)
#Firefox(6)
#Personal Data(6)
#Meta(6)
#EPMM(6)
#Kernel(6)
#LLM Security(6)
#Palo Alto Networks(6)
#Energy Sector(6)
#BitLocker(6)
#Heap Overflow(6)
#PraisonAI(6)
#Vulnerability Disclosure(6)
#South Korea(6)
#Research(6)
#Credential Stuffing(6)
#AI Agents(6)
#Check Point(6)
#Secrets Management(6)
#WhatsApp(6)
#IDOR(6)
#Signal(6)
#Telegram(6)
#Load Balancer(6)
#supply-chain(6)
#Google Chrome(6)
#Firewall(6)
#CVSS 10.0(6)
#Session Hijacking(6)
#ColdFusion(6)
#Database Security(6)
#REST API(6)
#JWT(6)
#SAML(6)
#CWE-287(6)
#Password Reset(6)
#PHP Object Injection(6)
#Wazuh(6)
#CVSS Critical(6)
#IP Camera(6)
#Legal(5)
#Data Extortion(5)
#Scattered Spider(5)
#Deepfakes(5)
#Vishing(5)
#Gemini(5)
#Hacktivism(5)
#Sanctions(5)
#Telecommunications(5)
#MongoDB(5)
#AiTM(5)
#Extradition(5)
#PHI(5)
#Mandiant(5)
#CRM(5)
#SaaS Security(5)
#SGLang(5)
#Regulatory(5)
#Kimwolf(5)
#Initial Access Broker(5)
#F5(5)
#BIG-IP(5)
#Nation State(5)
#Post-Quantum(5)
#Wiper(5)
#Credential Security(5)
#Apache ActiveMQ(5)
#Patch Management(5)
#Virtualization(5)
#Windows Defender(5)
#Disaster Recovery(5)
#NIST(5)
#Regulatory Fine(5)
#Password Manager(5)
#Mozilla(5)
#Auth Bypass(5)
#MSP(5)
#AI Platform(5)
#Security Operations(5)
#Security Update(5)
#Network-Security(5)
#PoC(5)
#LiteSpeed(5)
#Web Shell(5)
#OWASP(5)
#ICS Security(5)
#Memory Safety(5)
#Australia(5)
#Data Exposure(5)
#social-engineering(5)
#SSH(5)
#threat-intelligence(5)
#AI Tools(5)
#MFA(5)
#Outage(5)
#Denial of Service(5)
#Ecommerce(5)
#MLflow(5)
#Remote Exploit(5)
#CVSS 9.6(5)
#Directory Traversal(5)
#itsourcecode(5)
#CWE-502(5)
#Identity Provider(5)
#PKI(5)
#Input Validation(5)
#Broadcom(5)
#Containers(5)
#threat-detection(5)
#Banking(4)
#Threat Actors(4)
#Fintech(4)
#CrowdStrike(4)
#Cloudflare(4)
#PhaaS(4)
#Spain(4)
#Data Theft(4)
#GlassWorm(4)
#Solana(4)
#Streaming(4)
#Unauthorized Access(4)
#NetScaler(4)
#CVE-2026-3055(4)
#European Commission(4)
#TrueConf(4)
#File Transfer(4)
#Software Security(4)
#DPRK(4)
#Redis(4)
#PostgreSQL(4)
#Penetration Testing(4)
#REvil(4)
#US Government(4)
#Unpatched(4)
#Storm-1175(4)
#NVIDIA(4)
#Snowflake(4)
#PDF(4)
#Business Email Compromise(4)
#Detection(4)
#EDR Bypass(4)
#Microsoft Teams(4)
#AppSec(4)
#Business Continuity(4)
#BeyondTrust(4)
#RMM(4)
#Checkmarx(4)
#Hospitality(4)
#Threat Actor(4)
#Copilot(4)
#Tor(4)
#FTC(4)
#Medtronic(4)
#Canvas(4)
#OFAC(4)
#Malvertising(4)
#2FA(4)
#Mini Shai-Hulud(4)
#Financial Security(4)
#Shai-Hulud(4)
#Defense(4)
#Election Security(4)
#Acquisitions(4)
#Governance(4)
#Drupal(4)
#Chromium(4)
#Arrest(4)
#Laravel(4)
#Gitea(4)
#23andMe(4)
#GlobalProtect(4)
#Dashlane(4)
#Brute Force(4)
#Pakistan(4)
#Cyber Policy(4)
#FFmpeg(4)
#SolarWinds(4)
#PeopleSoft(4)
#Enterprise Software(4)
#INC Ransomware(4)
#Code Execution(4)
#StealC(4)
#Industry News(4)
#Threat Hunting(4)
#Embedded Security(4)
#ai-security(4)
#GitLab(4)
#Data Security(4)
#Credential Exposure(4)
#Remote Access(4)
#Apache Tomcat(4)
#Authentication(4)
#zero-trust(4)
#SCADA(4)
#Coolify(4)
#CSRF(4)
#CPAN(4)
#Cross-Site Scripting(4)
#Stack Overflow(4)
#CWE-121(4)
#AJAX(4)
#CWE-269(4)
#CVSS 9.9(4)
#Arbitrary File Write(4)
#PowerProtect(4)
#Education Software(4)
#SSO(4)
#Unauthenticated Access(4)
#Embedded Device(4)
#SSTI(4)
#CWE-347(4)
#CWE-639(4)
#SiYuan(4)
#Knowledge Management(4)
#vm2(4)
#Avi Load Balancer(4)
#APSB26-68(4)
#OT(4)
#File Write(4)
#Thunderbird(4)
#Network Devices(4)
#MSI(4)
#blue-team(4)
#DFIR(4)
#Conditional Access(4)
#XDR(4)
#Intune(4)
#device-control(4)
#Verizon(3)
#Antitrust(3)
#DHS(3)
#Trends(3)
#Lapsus$(3)
#Aviation(3)
#Biometrics(3)
#Age Verification(3)
#Italy(3)
#Semiconductor(3)
#Amazon(3)
#Logistics(3)
#Israel(3)
#ALPHV(3)
#Guilty Plea(3)
#Defense Strategy(3)
#Bug(3)
#Cybercrime Takedown(3)
#MDM(3)
#CVE-2026-2441(3)
#Financial Services(3)
#Akira(3)
#Hardware Security(3)
#AI Infrastructure(3)
#Trivy(3)
#DarkSword(3)
#Web Skimmer(3)
#Hacktivist(3)
#Steganography(3)
#CVE-2025-53521(3)
#Spear-Phishing(3)
#NCII(3)
#FCC(3)
#California(3)
#UNC1069(3)
#Hack(3)
#Crypto Heist(3)
#Drift Protocol(3)
#Governance Attack(3)
#Shadowserver(3)
#Chainguard(3)
#SBOM(3)
#Texas(3)
#Germany(3)
#Zendesk(3)
#Black Hat(3)
#GandCrab(3)
#DNS Hijacking(3)
#Medusa(3)
#IC3(3)
#Investment Fraud(3)
#Ninja Forms(3)
#IAM(3)
#cyber insurance(3)
#Acrobat Reader(3)
#Online Safety Act(3)
#Mirai(3)
#Water Security(3)
#Performance(3)
#Piracy(3)
#CVE-2026-3844(3)
#ADT(3)
#Bitwarden(3)
#JFrog(3)
#Exchange Server(3)
#Consumer Security(3)
#Have I Been Pwned(3)
#Zero-Click(3)
#Medical Devices(3)
#Crypto Fraud(3)
#Robotics(3)
#ConnectWise(3)
#OpenEMR(3)
#Child Safety(3)
#Go(3)
#Instructure(3)
#Trellix(3)
#RansomHouse(3)
#WHM(3)
#CCPA(3)
#Higher Education(3)
#Windows Security(3)
#Venture Capital(3)
#FortiSandbox(3)
#Pharmaceutical(3)
#Foxconn(3)
#Corporate Security(3)
#Exchange(3)
#Source Code Theft(3)
#Responsible Disclosure(3)
#7-Eleven(3)
#Bug Bounty(3)
#Industry Analysis(3)
#App Store(3)
#CMS Security(3)
#Bulletproof Hosting(3)
#BYOVD(3)
#Social Media(3)
#Consumer Privacy(3)
#VPN Security(3)
#Frontier AI(3)
#Domain Controller(3)
#Residential Proxy(3)
#EDR Evasion(3)
#VoIP(3)
#Risk Assessment(3)
#Smart TV(3)
#Serv-U(3)
#JetBrains(3)
#SocGholish(3)
#Industrial Security(3)
#AI Governance(3)
#Wallet Security(3)
#FortiBleed(3)
#Pig Butchering(3)
#Browser Extension(3)
#Insurance(3)
#Cursor IDE(3)
#India(3)
#Reconnaissance(3)
#CVE-2026-15409(3)
#CVE-2026-15410(3)
#OpenSSL(3)
#Machine Learning Security(3)
#Arista(3)
#Autonomous Attacks(3)
#Payment Security(3)
#N-able(3)
#Webmail(3)
#Business Intelligence(3)
#phishing(3)
#MITM(3)
#open-source(3)
#Statistics(3)
#M365(3)
#Notepad++(3)
#Google TAG(3)
#CVE-2026-1731(3)
#ZKTeco(3)
#CWE-434(3)
#Tenda(3)
#SOHO(3)
#CORS(3)
#Data Domain(3)
#Apache Airflow(3)
#Remote Exploitation(3)
#WebSphere(3)
#Wordfence(3)
#Improper Authentication(3)
#File Deletion(3)
#Missing Authentication(3)
#CodeIgniter(3)
#MySQL(3)
#Admin Panel(3)
#Arbitrary File Upload(3)
#Server-Side Request Forgery(3)
#LibRaw(3)
#RAW Image(3)
#Reverse Proxy(3)
#Domain User(3)
#CWE-284(3)
#Spinnaker(3)
#CWE-22(3)
#Template Injection(3)
#Out-of-Bounds(3)
#ZITADEL(3)
#Network Device(3)
#Unbound(3)
#Canonical(3)
#MiTM(3)
#Apache Camel(3)
#Image Processing(3)
#SAIL(3)
#Hard-Coded Credentials(3)
#Server Administration(3)
#Apache MINA(3)
#authentik(3)
#CWE-306(3)
#GitOps(3)
#Injection(3)
#OpENer(3)
#EtherNet/IP(3)
#CIP(3)
#migration-planner(3)
#ERP(3)
#End of Life Software(3)
#FortiOS(3)
#vulnerability-scanning(3)
#IDS(3)
#intrusion-detection(3)
#intrusion-prevention(3)
#Logging(3)
#endpoint-security(3)
#Security Baseline(3)
#linux(3)
#SOAR(3)