Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2724+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
Browse by Topic

All Tags

Explore our content organized by topic. Click on any tag to see related articles.

Popular Tags

#Vulnerability510 articles

• Android March 2026 Security Update Patches 129

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

View all
#CVE457 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

View all
#RCE377 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

View all
#Data Breach336 articles

• ShinyHunters Dumps 5.1 Million Panera Bread Customer

• Substack Discloses Data Breach After 100-Day Undetected

• Fintech Giant Figure Technology Confirms Breach: Nearly 1

View all
#Supply Chain290 articles

• WEF Global Cybersecurity Outlook 2026 Warns of 'Permanent

• Cline CLI Supply Chain Attack Installs Unauthorized

• Japanese Semiconductor Giant Advantest Hit by Ransomware

View all
#Ransomware246 articles

• ShinyHunters Dumps 5.1 Million Panera Bread Customer

• Ransomware in 2026: Data-Only Extortion Replaces Encryption

• HellCat Ransomware Group Breaches Ascom, Exfiltrates 44GB

View all
#Cybercrime228 articles

• WormGPT Hacked: 19,000 Cybercriminal AI Platform Users

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

View all
#Zero-Day207 articles

• Ex-L3Harris Executive Pleads Guilty to Selling Eight

• CrowdStrike 2026 Threat Report: eCrime Breakout Time Falls

• U.S. Treasury Sanctions Russian Zero-Day Broker Operation

View all
#WordPress204 articles

• File Read Flaw in Smart Slider Plugin Impacts 500K

• Hackers Exploit Critical Flaw in Ninja Forms WordPress

• Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

View all
#Malware201 articles

• PromptSpy: First Android Malware to Weaponize Generative AI

• Google Disrupts Massive Chinese Espionage Campaign

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

View all
#NVD175 articles

• NIST to Stop Rating Non-Priority Flaws Due to Volume

• Federal Audit Reveals NIST's NVD Is Plagued by Poor Planning and Duplication

• AI Is Accelerating Vulnerability Discovery — Can Defenders Keep Up?

View all
#Threat Intelligence170 articles

• Ransomware in 2026: Data-Only Extortion Replaces Encryption

• AI-Driven Threats Accelerate: Agentic Attacks, Model

• AI-Armed Amateur Hacker Compromises 600+ FortiGate

View all
#Critical165 articles

• Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

• New FortiClient EMS Flaw Exploited in Attacks, Emergency

• New Critical Exim Mailer Flaw Allows Remote Code Execution

View all
#BleepingComputer164 articles

• Telus Digital Confirms Massive Breach After ShinyHunters

• AppsFlyer Web SDK Supply Chain Attack Spread

• CISA Adds Wing FTP Server Flaw to KEV as RCE Chain Exploits

View all
#AI Security158 articles

• AI-Driven Threats Accelerate: Agentic Attacks, Model

• WormGPT Hacked: 19,000 Cybercriminal AI Platform Users

• Cline CLI Supply Chain Attack Installs Unauthorized

View all
#Microsoft152 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Microsoft Releases Windows 11 OOB Hotpatch to Fix Three

• Windows 11 February Update Breaks C:\ Drive Access on Samsung PCs

View all
#SQL Injection138 articles

• Hackers Are Exploiting a Critical LiteLLM Pre-Auth SQLi Flaw

• Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

• Drupal: Critical SQL Injection Flaw Now Targeted in Attacks

View all
#Privilege Escalation128 articles

• Cisco Patches Critical and High-Severity Vulnerabilities

• Disgruntled Researcher Leaks BlueHammer Windows Zero-Day

• GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables

View all
#Web Security125 articles

• AppsFlyer Web SDK Supply Chain Attack Spread

• Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

• Avada Builder WordPress Plugin Flaws Allow Site Credential

View all
#Security Updates123 articles

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

View all
#Cloud Security112 articles

• Google's $32 Billion Wiz Acquisition Clears Final Hurdle as

• CrowdStrike 2026 Threat Report: eCrime Breakout Time Falls

• Cloudflare 2026 Threat Report: 230 Billion Daily Threats as

View all
#The Hacker News109 articles

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

• GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison

• Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach

View all
#Authentication Bypass109 articles

• Cisco Patches Critical and High-Severity Vulnerabilities

• Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables

• Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now

View all
#Windows107 articles

• Microsoft Releases Windows 11 OOB Hotpatch to Fix Three

• Microsoft Shares Fix for Windows C: Drive Access Issues on Samsung PCs

• Microsoft Halts Forced Global Rollout of Microsoft 365

View all
#Remote Code Execution93 articles

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

• Critical Langflow RCE Flaw Exploited Within 20 Hours of Disclosure

• CISA: New Langflow Flaw Actively Exploited to Hijack AI

View all
#Law Enforcement86 articles

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

View all
#APT78 articles

• Leaked Documents Reveal China's 'Expedition Cloud' Cyber

• Google Disrupts Massive Chinese Espionage Campaign

• Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

View all
#CISA KEV78 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• CISA Adds Wing FTP Server Flaw to KEV as RCE Chain Exploits

View all
#Healthcare75 articles

• Ransomware in 2026: Data-Only Extortion Replaces Encryption

• Ransomware Forces University of Mississippi Medical Center

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

View all
#Phishing74 articles

• Diesel Vortex: Russian Cybercrime Ring Steals 1,649

• Operation Epic Fury Triggers Unprecedented Cyber Escalation

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

View all
#PHP74 articles

• Microsoft Details Cookie-Controlled PHP Web Shells

• Laravel Lang Packages Hijacked to Deploy

• Laravel-Lang PHP Packages Compromised to Deliver

View all
#Security74 articles

• Apple Blocked Over $11 Billion in App Store Fraud in 6 Years

• Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention

• npm Adds 2FA-Gated Publishing and Package Install Controls

View all
#Nation-State69 articles

• Senator Demands AT&T, Verizon CEOs Testify Over Salt

• Operation Epic Fury Triggers Unprecedented Cyber Escalation

• Cloudflare 2026 Threat Report: 230 Billion Daily Threats as

View all
#npm69 articles

• UNC6426 Weaponizes Old nx npm Compromise to Seize AWS Admin Access

• CanisterWorm: First Blockchain-Powered Self-Spreading Worm

• Attack on Axios Developer Tool Threatens Widespread

View all
#Russia68 articles

• Ex-L3Harris Executive Pleads Guilty to Selling Eight

• Pro-Russian Hacktivists Launch Sustained Cyber Campaign

• APT28 Operation MacroMaze: Russia-Linked Hackers Hit

View all
#Critical Infrastructure65 articles

• CISA Loses 62% of Workforce as DHS Shutdown Guts America's

• Japanese Semiconductor Giant Advantest Hit by Ransomware

• Ransomware Forces University of Mississippi Medical Center

View all
#AI65 articles

• Anthropic Exposes Industrial-Scale AI Distillation Attacks

• CrowdStrike 2026 Threat Report: eCrime Breakout Time Falls

• AI-Armed Amateur Hacker Compromises 600+ FortiGate

View all
#Command Injection63 articles

• Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks

• NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

• Attackers Chain Two SonicWall SMA 1000 Zero-Days in Active Attacks

View all
#Privacy62 articles

• Substack Discloses Data Breach After 100-Day Undetected

• IRS Shares Tax Data of 1.28 Million Individuals with DHS

• Persona Source Code Leak Exposes Hidden Biometric

View all
#Google60 articles

• Google's $32 Billion Wiz Acquisition Clears Final Hurdle as

• Google Disrupts Massive Chinese Espionage Campaign

• Android March 2026 Security Update Patches 129

View all
#Linux57 articles

• Critical Unpatched GNU Telnetd Flaw (CVE-2026-32746)

• Microsoft Details Cookie-Controlled PHP Web Shells

• New 'Pack2TheRoot' Flaw Gives Hackers Root Linux Access

View all
#CISA56 articles

• CISA Loses 62% of Workforce as DHS Shutdown Guts America's

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC

View all
#Social Engineering53 articles

• Scattered Lapsus$ ShinyHunters Alliance Hits 100+

• Fintech Giant Figure Technology Confirms Breach: Nearly 1

• Axios npm Hack Used Fake Teams Error Fix to Hijack

View all
#Cryptocurrency53 articles

• North Korea's UNC4899 Breached Crypto Firm via AirDropped

• AppsFlyer Web SDK Supply Chain Attack Spread

• Hacker Walks Away with $24.5 Million After Breaching Resolv

View all
#Open Source52 articles

• Cline CLI Supply Chain Attack Installs Unauthorized

• Betterleaks: New Open-Source Secrets Scanner Built to Replace Gitleaks

• Claude Code Source Code Accidentally Leaked in NPM Package

View all
#Network Security52 articles

• Critical Unpatched GNU Telnetd Flaw (CVE-2026-32746)

• Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active

• Fortinet Warns of Critical RCE Flaws in FortiSandbox and FortiAuthenticator

View all
#Unauthenticated52 articles

• WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

• Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

• CVE-2016-20052: Snews CMS 1.7 Unrestricted File Upload

View all
#China51 articles

• Senator Demands AT&T, Verizon CEOs Testify Over Salt

• Anthropic Exposes Industrial-Scale AI Distillation Attacks

• Leaked Documents Reveal China's 'Expedition Cloud' Cyber

View all
#Credential Theft51 articles

• Diesel Vortex: Russian Cybercrime Ring Steals 1,649

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

View all
#Account Takeover49 articles

• Device Code Phishing Attacks Surge 37x as New Kits Spread

• Why Chargebacks Are Just One Piece of the Fraud Puzzle

• Hackers Used Meta's AI Support Bot to Seize Instagram Accounts

View all
#Espionage46 articles

• Ex-L3Harris Executive Pleads Guilty to Selling Eight

• APT28 Operation MacroMaze: Russia-Linked Hackers Hit

• Leaked Documents Reveal China's 'Expedition Cloud' Cyber

View all
#Patch Tuesday46 articles

• Android March 2026 Security Update Patches 129

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

• Microsoft Releases Windows 11 OOB Hotpatch to Fix Three

View all
#Active Exploitation46 articles

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active

• CISA: New Langflow Flaw Actively Exploited to Hijack AI

View all
#Path Traversal46 articles

• Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks

• 7 Unpatched Flaws Disclosed in FatFs Filesystem Used in Millions of Embedded Devices

• Progress Confirms ShareFile Zero-Day Flaw Behind Storage Zone Shutdown

View all
#ShinyHunters44 articles

• ShinyHunters Dumps 5.1 Million Panera Bread Customer

• Scattered Lapsus$ ShinyHunters Alliance Hits 100+

• Fintech Giant Figure Technology Confirms Breach: Nearly 1

View all
#File Upload43 articles

• Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

• Forminator WordPress Plugin Flaw Enables Unauthenticated RCE via PHP Upload

• Elementor Pro Flaw Exploited to Hack WordPress Sites, 190K+ Attempts Blocked

View all
#IoT42 articles

• DoJ Disrupts 3 Million-Device IoT Botnets Behind Record

• Weekly Recap: CI/CD Backdoor, FBI Buys Location Data

• Feds Disrupt IoT Botnets Behind Huge DDoS Attacks

View all
#Router42 articles

• Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

• Cisco IOS XE Web UI Privilege Escalation Actively Exploited

• CVE-2024-51311: Critical Stack Overflow in Tenda TX9 Router Firmware

View all
#Plugin Vulnerability40 articles

• WP Maps Pro Bug Exploited to Create Admin Accounts on WordPress Sites

• CVE-2016-20066: WordPress CP Polls Persistent XSS via File Upload

• CVE-2026-12761: miniOrange WordPress Social Login Auth Bypass Enables Full Admin Takeover

View all
#GitHub39 articles

• UNC6426 Weaponizes Old nx npm Compromise to Seize AWS Admin Access

• GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison

• The State of Secrets Sprawl 2026: 9 Takeaways for CISOs

View all
#sentinelone39 articles

• The Good, the Bad and the Ugly in Cybersecurity – Week 14

• Hypersonic Supply Chain Attacks: AI Defense Stops Zero-Days

• Researchers Uncover Pre-Stuxnet 'fast16' Malware Targeting

View all
#automation39 articles

• How to Configure Microsoft Sentinel Analytics Rules

• Automating Report Generation with Python and Jinja2

• Automated News Aggregation with Deduplication Algorithms

View all
#Government38 articles

• IRS Shares Tax Data of 1.28 Million Individuals with DHS

• LexisNexis Confirms Cloud Breach Exposing 400K User

• European Commission Confirms Data Breach After Europa.eu

View all
#Cisco38 articles

• Interlock Ransomware Has Been Exploiting Cisco FMC Zero-Day

• CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC

• Interlock Ransomware Exploited Cisco FMC Zero-Day for 36

View all
#edr38 articles

• Trellix Source Code Breach Highlights Growing Supply Chain

• Gentlemen Ransomware Uses Multiple EDR Killers to Disable Defenses

• GodDamn Ransomware Deploys Microsoft-Signed PoisonX Driver to Kill EDR Tools

View all
#SourceCodester38 articles

• CVE-2025-69941: Critical SQL Injection in Tailor Management System — Measurement Endpoint

• CVE-2025-69947: Critical SQL Injection in Tailor Management System — Customer Edit Endpoint

• CVE-2026-10184: SourceCodester Hospital Records SQL Injection via Delete

View all
#AWS37 articles

• LexisNexis Confirms Cloud Breach Exposing 400K User

• UNC6426 Weaponizes Old nx npm Compromise to Seize AWS Admin Access

• AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable

View all
#Infostealer37 articles

• VoidStealer Malware Steals Chrome Master Key via Debugger

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• Trivy Supply Chain Attack Targets CI/CD Secrets

View all
#Fraud37 articles

• Adversaries Exploit Vacant Homes to Intercept Mail in Hybrid Cybercrime

• FCC Proposes $4.5 Million Fine for Voice Provider Hosting

• Over 20,000 Crypto Fraud Victims Identified in International Crackdown

View all
#Android36 articles

• PromptSpy: First Android Malware to Weaponize Generative AI

• Android March 2026 Security Update Patches 129

• Android 17 Blocks Non-Accessibility Apps from Accessibility

View all
#XSS36 articles

• Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks

• Microsoft Exchange Zero-Day Under Attack, No Patch Available

• Zimbra Urges Customers to Patch Critical Web Client XSS Flaw Exploited in the Wild

View all
#Critical Vulnerability36 articles

• Fortinet Warns of Critical RCE Flaws in FortiSandbox and FortiAuthenticator

• Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites

• Cisco Patches Critical Webex Vulnerability Allowing Remote

View all
#policy34 articles

• CISA Loses 62% of Workforce as DHS Shutdown Guts America's

• Here's How the FTC Plans to Enforce the Take It Down Act

• Can Laws Stop Deepfakes? South Korea Aims to Find Out

View all
#Fortinet34 articles

• AI-Armed Amateur Hacker Compromises 600+ FortiGate

• Critical Fortinet FortiClient EMS Flaw Now Exploited in Attacks

• Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

View all
#DevSecOps34 articles

• Betterleaks: New Open-Source Secrets Scanner Built to Replace Gitleaks

• The State of Secrets Sprawl 2026: 9 Takeaways for CISOs

• Cisco Source Code Stolen in Trivy-Linked Dev Environment

View all
#Docker34 articles

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• Malicious KICS Docker Images and VS Code Extensions Hit

• Open Source DockSec Uses AI to Cut Through Vulnerability

View all
#Deserialization34 articles

• PTC Warns of Imminent Threat from Critical Windchill

• Critical Flaw in protobuf.js Library Enables JavaScript

• Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

View all
#Buffer Overflow34 articles

• Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches

• CVE-2016-20049: JAD Java Decompiler Stack-Based Buffer

• CVE-2017-20225: TiEmu TI Calculator Emulator Stack Buffer

View all
#OpenAI33 articles

• Persona Source Code Leak Exposes Hidden Biometric

• OpenAI Says ChatGPT Ads Are Not Rolling Out Globally For Now

• ChatGPT Rolls Out New $100 Pro Subscription to Challenge

View all
#North Korea32 articles

• North Korea's UNC4899 Breached Crypto Firm via AirDropped

• Axios NPM Package Breached in North Korean Supply Chain

• Google Attributes Axios npm Supply Chain Attack to North

View all
#Incident Response32 articles

• Stryker Cyberattack Wiped Tens of Thousands of Devices — No

• Dutch Finance Ministry Takes Treasury Banking Portal

• The Backup Myth That Is Putting Businesses at Risk

View all
#Botnet32 articles

• DoJ Disrupts 3 Million-Device IoT Botnets Behind Record

• Manager of Botnet Used in Ransomware Attacks Gets 2 Years

• Feds Disrupt IoT Botnets Behind Huge DDoS Attacks

View all
#Anthropic31 articles

• Anthropic Exposes Industrial-Scale AI Distillation Attacks

• Claude Code Source Code Accidentally Leaked in NPM Package

• Claude Code Source Leaked via npm Packaging Error

View all
#Python31 articles

• GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison

• Supply Chain Attack Hits Widely-Used AI Package, Risking

• Backdoored Telnyx PyPI Package Pushes Malware Hidden in WAV

View all
#IoT Security31 articles

• ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache

• Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack

• EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

View all
#VPN31 articles

• Hackers Bypass SonicWall VPN MFA Due to Incomplete Patching

• Europe Dismantles VPN Service Used by Cybercriminals to Hide Ransomware Attacks

• Police Seize 'First VPN' Service Used in Ransomware and Data Theft Attacks

View all
#CWE-8931 articles

• CVE-2019-25662: ResourceSpace 8.6 Unauthenticated SQL

• Critical Blind SQL Injection in Akilli E-Commerce Website

• CVE-2025-62319: Critical SQL Injection in HCL Unica (CVSS

View all
#ICS30 articles

• ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days

• Accenture to Acquire Majority Stake in Dragos, runZero, and NetRise in $4.1 Billion OT Cybersecurity Push

• Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack

View all
#threat-hunting30 articles

• Velociraptor DFIR Setup, Hunts, and Forensic Collection

• Osquery Endpoint Visibility & Threat Hunting

• Linux auditd: Kernel-Level Security Monitoring and Compliance Logging

View all
#ClickFix29 articles

• Termite Ransomware Operator Velvet Tempest Chains ClickFix

• LeakNet Ransomware Weaponizes ClickFix and Deno Runtime for Stealthy Corporate Attacks

• Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

View all
#TeamPCP29 articles

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• Trivy Supply Chain Attack Targets CI/CD Secrets

• TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides

View all
#Chrome28 articles

• VoidStealer Malware Steals Chrome Master Key via Debugger

• Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in 2026

• New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation

View all
#Extortion28 articles

• Former DigitalMint Ransomware Negotiator Pleads Guilty to $75.3M Extortion Scheme

• ADT Confirms Data Breach After ShinyHunters Leak Threat

• New BlackFile Extortion Group Linked to Surge of Vishing

View all
#OS Command Injection28 articles

• CVE-2026-10520: Ivanti Sentry OS Command Injection — CVSS 10.0

• CVE-2026-15511: Critical OS Command Injection in Comfast CF-WR631AX Router

• CVE-2026-27130 — Dokploy OS Command Injection via appName

View all
#Apple27 articles

• CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog

• Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple

• Apple Expands iOS 18 Updates to More iPhones to Block

View all
#firewall27 articles

• Firestarter Malware Survives Cisco Firewall Updates and Security Patches

• FIRESTARTER Backdoor Hit Federal Cisco Firepower Device

• FortiBleed: Russian IAB Harvested 110 Million Credentials from 430,000 FortiGate Firewalls

View all
#deployment27 articles

• SentinelOne Application Control Policies

• SentinelOne Control vs Complete Feature Comparison

• SentinelOne Create and Manage Exclusion Policies

View all
#detection-rules27 articles

• SentinelOne Application Control Policies

• SentinelOne Control vs Complete Feature Comparison

• SentinelOne Create and Manage Exclusion Policies

View all
#FBI26 articles

• FBI Warns of ATM Jackpotting Surge as Losses Top $20

• Ransomware Forces University of Mississippi Medical Center

• FBI Warns Russian Intelligence Targeting Signal and WhatsApp in Mass Phishing Campaign

View all
#Agentic AI26 articles

• AI-Driven Threats Accelerate: Agentic Attacks, Model

• OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click

• Shadow AI in SaaS: How Hidden AI Agents Are Enabling

View all
#Developer Security26 articles

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

• GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison

• Attack on Axios Developer Tool Threatens Widespread

View all
#Web Application26 articles

• Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites

• Apache Struts Critical RCE via OGNL Injection Returns

• CVE-2018-25362: Twitter-Clone SQL Injection via follow.php

View all
#api26 articles

• OpenAI Temporarily Relaxes GPT-5.6 Sol Usage Limits Amid Demand Surge

• FortiGate Firewall Policy Management with PowerShell

• SentinelOne Application Control Policies

View all
#Authorization Bypass26 articles

• Coolify CVE-2026-34047: Terminal WebSocket Authorization Bypass (CVSS 9.9)

• CVE-2026-11807: Critical Authorization Bypass in Event-Driven Ansible WebSocket API

• CVE-2026-12153: WP Learn Manager Plugin — Unauthenticated Authorization Bypass Allows Plugin Installation

View all
#Mobile Security25 articles

• PromptSpy: First Android Malware to Weaponize Generative AI

• Android March 2026 Security Update Patches 129

• Android 17 Blocks Non-Accessibility Apps from Accessibility

View all
#DOJ25 articles

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

• DoJ Disrupts 3 Million-Device IoT Botnets Behind Record

View all
#SSRF25 articles

• LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

• CVE-2026-20230: Cisco Unified CM WebDialer SSRF Now Exploited in the Wild

• SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

View all
#Azure25 articles

• Microsoft Patch Tuesday, March 2026 Edition

• ConsentFix v3 Automates Azure OAuth Abuse With Mass

• Microsoft Rejects Critical Azure Vulnerability Report, No

View all
#macOS24 articles

• Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

• New Infinity Stealer Malware Grabs macOS Data via ClickFix

• In Other News: ChatGPT Data Leak, Android Rootkit, Water

View all
#WooCommerce24 articles

• Funnel Builder WordPress Plugin Bug Exploited to Steal

• Funnel Builder Flaw Under Active Exploitation Enables

• CVE-2025-10656: WooCommerce Plugin Missing Authorization Allows Unauthenticated Admin Account Creation

View all
#incident-response24 articles

• Ransom Busters: Ransomware Affiliate Poses as Data Recovery Firm

• Network Traffic Analysis with Zeek: From Deployment to Threat Detection

• Velociraptor DFIR Setup, Hunts, and Forensic Collection

View all
#Code Injection23 articles

• Actively Exploited Apache ActiveMQ Flaw Impacts 6,400

• Critical Unauthenticated Hook Injection in ComboBlocks WordPress Plugin

• CVE-2025-32432: Craft CMS Code Injection Vulnerability

View all
#CVSS 9.823 articles

• CVE-2026-10042: manga-image-translator RCE via Unsafe Python Deserialization

• CVE-2026-11849: IRM-IEI Remote Management Hardcoded Credentials

• CVE-2026-14894: WordPress Super Forms Plugin Critical Arbitrary File Upload

View all
#Enterprise Security22 articles

• Google: 90 Zero-Days Exploited in 2025 — Enterprise Tech

• New Progress ShareFile Flaws Can Be Chained in Pre-Auth RCE

• Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively

View all
#Sandbox Escape22 articles

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

• Edgecution: Malicious Edge Extension Escapes Browser Sandbox via Native Messaging

• n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

View all
#KEV22 articles

• CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• CISA: New Langflow Flaw Actively Exploited to Hijack AI

View all
#SecurityWeek22 articles

• Navia Data Breach Impacts 2.7 Million People

• Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

• Cisco Patches Critical and High-Severity Vulnerabilities

View all
#Ukraine21 articles

• Spanish-Ukrainian Police Bust Gambling Ring That Exploited

• Pro-Ukraine Hacker Group Bearlyfy Targets Russian Companies

• Bearlyfy Hits Russian Firms with Custom GenieLocker

View all
#Kubernetes21 articles

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• VoidLink: AI-Generated Cloud-Native Malware Framework

• CVE-2025-69902: Critical Command Injection in kubectl-mcp-server

View all
#Browser Security21 articles

• Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in 2026

• New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation

• Microsoft Backpedals: Edge to Stop Loading Cleartext

View all
#Email Security21 articles

• Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks

• New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

• Microsoft Warns of Exchange Zero-Day Flaw Exploited in Attacks

View all
#Node.js21 articles

• Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

• NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

• Amazon Links Debug, Chalk NPM Supply Chain Attacks to North Korean Hackers

View all
#API Security21 articles

• South Korean Startup Platform Breach Exposes Critical Key Management Failures

• CVE-2025-71327: Flowise Authentication Bypass Grants Full API Access

• CVE-2026-14450: MaaS API Auth Bypass via Forged HTTP Headers

View all
#Iran20 articles

• Iran Plunged Into Digital Darkness: Internet Drops to 4% in Cyberattack

• Operation Epic Fury Triggers Unprecedented Cyber Escalation

• Iran-Linked Hackers Breach FBI Director's Personal Email

View all
#CI/CD20 articles

• UNC6426 Weaponizes Old nx npm Compromise to Seize AWS Admin Access

• Trivy Security Scanner GitHub Actions Breached — 75 Tags

• Trivy Supply Chain Attack Targets CI/CD Secrets

View all
#E-Commerce19 articles

• PolyShell Attacks Target 56% of All Vulnerable Magento

• WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

• Hackers Use Pixel-Large SVG Trick to Hide Credit Card

View all
#Container Security19 articles

• The State of Trusted Open Source Report: Key Findings for 2025

• Chainguard Unveils Factory 2.0 to Automate Hardening the Software Supply Chain

• Open Source DockSec Uses AI to Cut Through Vulnerability

View all
#Homelab19 articles

• Building a Secure Homelab in 2026: Complete Guide

• Keycloak SSO: Self-Hosted Identity Provider for Your Homelab

• Build a Collaborative IPS with CrowdSec

View all
#Cybersecurity18 articles

• WEF Global Cybersecurity Outlook 2026 Warns of 'Permanent

• Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

• Trellix Confirms Source Code Breach With Unauthorized

View all
#Third-Party Risk18 articles

• Ericsson US Discloses Data Breach Affecting Employees and Customers

• Marquis Ransomware Breach: 672K People Exposed as Attack

• Hims & Hers Warns of Data Breach After Zendesk Support

View all
#Oracle18 articles

• Oracle Pushes Emergency Fix for Critical Identity Manager

• Oracle Mitigates PeopleSoft Zero-Day Exploited in Data Theft Attacks

• ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities

View all
#Claude18 articles

• Claude Code Source Leaked via npm Packaging Error

• Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws

• Can Anthropic Keep Its Exploit-Writing AI Out of the Wrong

View all
#SonicWall18 articles

• ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force

• Hackers Bypass SonicWall VPN MFA Due to Incomplete Patching

• SonicWall Warns of SMA1000 Flaws Exploited in Zero-Day Attacks, Patch Now

View all
#D-Link18 articles

• New Mirai Campaign Exploits RCE Flaw in End-of-Life D-Link

• CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal

• AryStinger Botnet Infected Thousands of D-Link Routers Worldwide

View all
#OT Security18 articles

• EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

• Exposed Fuel Tank Gauges Under Attack in the US

• Australian Sugar Producer Works to Restore Operations After Ransomware Attack

View all
#Java18 articles

• Fastjson 1.x RCE Actively Exploited With No Patch Available

• Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patch Available

• Hackers Target US Firms in FastJson RCE Zero-Day Attacks

View all
#Takedown17 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3

• Police Seize 'First VPN' Service Used in Ransomware and Data Theft Attacks

View all
#Prompt Injection17 articles

• OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click

• Microsoft, Salesforce Patch AI Agent Data Leak Flaws

• New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

View all
#Patch Now17 articles

• Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks

• Critical Fortinet FortiClient EMS Flaw Now Exploited in Attacks

• Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE

View all
#Compliance17 articles

• Healthcare Software Firm CareCloud Informs SEC of Potential

• DORA and Operational Resilience: Credential Management as a

• New Initiative Tackles Security for End-of-Life Open Source Software

View all
#Identity Security17 articles

• Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks

• Why Simple Breach Monitoring Is No Longer Enough

• Your Next Breach Will Look Like Business as Usual

View all
#Backdoor17 articles

• Axios NPM Package Breached in North Korean Supply Chain

• China-Linked APT GopherWhisper Abuses Legitimate Services

• CryptoBandits Malware Doubles as a Backdoor, Abuses Tor for Stealthy C2

View all
#SIEM17 articles

• Only 10% of SOCs Say They're Getting Excellent Value From AI — What the Second Wave Must Deliver

• Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

• CVE-2026-17561: Critical Code Injection in Logsign SIEM

View all
#PowerShell17 articles

• TerminalFix ClickFix Variant Deploys Reverse-Tunnel Backdoor

• Microsoft Warns of TerminalFix Attacks Deploying Reverse Tunnels

• ClickFix Attacks Evolve to Abuse DNS nslookup for Payload Delivery

View all
#Telecom16 articles

• Senator Demands AT&T, Verizon CEOs Testify Over Salt

• Ericsson US Discloses Data Breach Affecting Employees and Customers

• Telus Digital Confirms Massive Breach After ShinyHunters

View all
#PII16 articles

• Japan Airlines Confirms Data Breach Affecting 28,000

• IDMerit KYC Data Breach Exposes 1 Billion Records Across 26

• Ericsson US Discloses Data Breach Affecting Employees and Customers

View all
#DDoS16 articles

• Pro-Russian Hacktivists Launch Sustained Cyber Campaign

• Iran Plunged Into Digital Darkness: Internet Drops to 4% in Cyberattack

• Cloudflare 2026 Threat Report: 230 Billion Daily Threats as

View all
#Salesforce16 articles

• ShinyHunters Claims Mass Data Theft From 400 Firms via Salesforce Aura

• Microsoft, Salesforce Patch AI Agent Data Leak Flaws

• 7-Eleven Data Breach Confirmed After ShinyHunters Ransom

View all
#JavaScript16 articles

• AppsFlyer Web SDK Supply Chain Attack Spread

• Critical Flaw in protobuf.js Library Enables JavaScript

• New npm Supply Chain Attack Self-Spreads to Steal Developer

View all
#GitHub Actions16 articles

• Trivy Security Scanner GitHub Actions Breached — 75 Tags

• Trivy Vulnerability Scanner Breached to Push Infostealer

• Trivy Supply Chain Attack Targets CI/CD Secrets

View all
#Langflow16 articles

• CISA: New Langflow Flaw Actively Exploited to Hijack AI

• Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks

• Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

View all
#Plugin Security16 articles

• File Read Flaw in Smart Slider Plugin Impacts 500K

• Avada Builder WordPress Plugin Flaws Allow Site Credential

• Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites

View all
#Endpoint Security16 articles

• Payouts King Ransomware Uses QEMU Virtual Machines to Bypass Endpoint Security

• Microsoft Warns of New Defender Zero-Days Exploited in Attacks

• Trend Micro Warns of Apex One Zero-Day Exploited in the Wild

View all
#CVSS 1016 articles

• Ubiquiti Patches Three Max-Severity UniFi OS Vulnerabilities

• Metabase SQLi Zero-Day Exploited in Customer Data-Theft Attacks

• CVE-2017-20230: Perl Storable Stack Overflow — CVSS 10.0

View all
#IBM16 articles

• IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under "Project Lightwell"

• Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.

• CVE-2025-36359: IBM DevOps Session Hijacking Vulnerability (CVSS 8.1)

View all
#Access Control16 articles

• FIFA Bug Exposes World Cup Streams to Remote Takeover

• Forget Data Leakage: Shadow AI's Real Threat Is Access Control

• CVE-2018-25391: HaPe PKH 1.1 Unauthenticated Record Deletion via Missing Authorization

View all
#forensics16 articles

• New Tool Traces AI-Generated Videos Back to Their Source

• Velociraptor DFIR Setup, Hunts, and Forensic Collection

• SentinelOne Control vs Complete Feature Comparison

View all
#Perl16 articles

• CVE-2009-10007: Catalyst::Plugin::Authentication Session Fixation

• CVE-2011-10043: Perl Module::Load Arbitrary Module Injection Resurfaces

• CVE-2017-20230: Perl Storable Stack Overflow — CVSS 10.0

View all
#Funding15 articles

• Cloud Security Startup Native Exits Stealth With $42

• Eclypsium Raises $25 Million to Expand Device Supply Chain

• Exaforce Raises $125 Million for Agentic SOC Platform

View all
#OAuth15 articles

• Shadow AI in SaaS: How Hidden AI Agents Are Enabling

• Device Code Phishing Attacks Surge 37x as New Kits Spread

• Vercel Employee's AI Tool Access Led to Data Breach

View all
#Patch15 articles

• Oracle Pushes Emergency Fix for Critical Identity Manager

• Hackers Now Exploit Critical F5 BIG-IP Flaw in Attacks

• Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

View all
#iOS15 articles

• CISA Adds Apple DarkSword iOS Exploits, Craft CMS, and Laravel Livewire Flaws to KEV Catalog

• DarkSword GitHub Leak Threatens to Turn Elite iPhone

• TA446 Deploys DarkSword iOS Exploit Kit in Targeted

View all
#DeFi15 articles

• Hacker Walks Away with $24.5 Million After Breaching Resolv

• Hacker Charged with Stealing $53 Million from Uranium

• Crypto Platform Drift Suspends Services After Hundreds of Millions Stolen

View all
#PyPI15 articles

• Supply Chain Attack Hits Widely-Used AI Package, Risking

• Backdoored Telnyx PyPI Package Pushes Malware Hidden in WAV

• TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides

View all
#GDPR15 articles

• Dutch Court Threatens xAI with Fines Over Grok's

• Italian Regulator Fines Financial Giant $36 Million for Data Protection Failures

• Italian Regulator Fines National Postal Service Orgs $15

View all
#Open Source Security15 articles

• The State of Trusted Open Source Report: Key Findings for 2025

• Axios npm Hack Used Fake Teams Error Fix to Hijack

• 13-Year-Old Bug in ActiveMQ Lets Hackers Remotely Execute

View all
#Adobe15 articles

• Adobe Reader Zero-Day Exploited via Malicious PDFs Since

• Hackers Exploiting Acrobat Reader Zero-Day Flaw Since

• Adobe Patches Actively Exploited Zero-Day That Lingered for Months

View all
#MCP15 articles

• Anthropic MCP Design Vulnerability Enables RCE, Threatening

• 2-Click Cursor Exploit Enables Dev Environment Takeover

• Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

View all
#VMware15 articles

• Kyber Ransomware Gang Uses Post-Quantum Encryption to Target Windows and ESXi

• Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL

• Hackers Earn $1,298,250 for 47 Zero-Days at Pwn2Own Berlin

View all
#Stored XSS15 articles

• CVE-2015-20115: RealtyScript 4.0.2 Stored XSS via File

• CVE-2026-10081: Unlimited Elements for Elementor Stored XSS via Google Reviews

• CVE-2026-15002: Stored XSS in Autopay WooCommerce Plugin for WordPress

View all
#Insider Threat14 articles

• Ex-L3Harris Executive Pleads Guilty to Selling Eight

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

• New Jersey Men Sentenced to Combined 17 Years for Running

View all
#Education14 articles

• ShinyHunters Dumps Harvard and UPenn Data After Ransom

• ShinyHunters Breach Infinite Campus — K-12 Platform Serving

• Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

View all
#Identity Theft14 articles

• AT&T Breach Data Resurfaces: 176 Million Records with Fully

• IDMerit KYC Data Breach Exposes 1 Billion Records Across 26

• Ericsson US Discloses Data Breach Affecting Employees and Customers

View all
#Europol14 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Spanish-Ukrainian Police Bust Gambling Ring That Exploited

• Operation Synergia III: Police Sinkhole 45,000 IPs in Global Cybercrime Crackdown

View all
#Firmware14 articles

• Eclypsium Raises $25 Million to Expand Device Supply Chain

• Flipper Zero Firmware Development Continues With Community Help

• Six U-Boot Flaws Could Enable Stealthy Firmware Attacks on Embedded Devices

View all
#Blockchain14 articles

• CanisterWorm: First Blockchain-Powered Self-Spreading Worm

• Hacker Walks Away with $24.5 Million After Breaching Resolv

• Google Slashes Quantum Resource Requirements for Breaking

View all
#Microsoft 36514 articles

• Device Code Phishing Attacks Surge 37x as New Kits Spread

• ConsentFix v3 Automates Azure OAuth Abuse With Mass

• Tycoon2FA Hijacks Microsoft 365 Accounts via Device-Code

View all
#Active Directory14 articles

• Why Changing Passwords Doesn't End an Active Directory

• Microsoft: Domain Controller Lookup May Fail on Windows

• Can You Enforce Strong Active Directory Password Rules Without Frustrating Users?

View all
#SD-WAN14 articles

• Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited

• Cisco Catalyst SD-WAN Controller Auth Bypass Actively

• Cisco Warns of Unpatched SD-WAN Zero-Day Exploited in Attacks

View all
#SiYuan14 articles

• CVE-2026-33669: SiYuan Unauthenticated Document Content

• CVE-2026-33670: SiYuan readDir Path Traversal Notebook

• CVE-2026-40259 — SiYuan Knowledge Management Authorization

View all
#mitre-attack14 articles

• SentinelOne Control vs Complete Feature Comparison

• SentinelOne Deep Visibility Threat Hunting

• SentinelOne File Fetch and Forensic File Collection

View all
#Dark Web13 articles

• WormGPT Hacked: 19,000 Cybercriminal AI Platform Users

• AT&T Breach Data Resurfaces: 176 Million Records with Fully

• Paid AI Accounts Are Now a Hot Underground Commodity

View all
#FortiGate13 articles

• AI-Armed Amateur Hacker Compromises 600+ FortiGate

• FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices

• FortiBleed Campaign Used Custom FortiGate Sniffer to Steal Credentials

View all
#HIPAA13 articles

• Cognizant TriZetto Breach Exposes Health Data of 3.4

• 3.1 Million Impacted by QualDerm Partners Data Breach

• 250,000 Affected by Data Breach at Nacogdoches Memorial

View all
#Netherlands13 articles

• Dutch Finance Ministry Takes Treasury Banking Portal

• Healthcare IT Provider ChipSoft Hit by Ransomware Attack

• Dutch Hospitals Disrupted After Ransomware Hits Healthcare

View all
#Security Research13 articles

• Black Hat USA 2026: What to Expect from the Year''s Biggest

• 1 Billion CISA KEV Records Reveal Human-Scale Security Has

• Analysis of 216M Security Findings Shows a 4x Increase in Critical Risk (2026 Report)

View all
#Artificial Intelligence13 articles

• Commerce Setting Up New AI Export Regime to Push Adoption

• Google Detects First AI-Generated Zero-Day Exploit in the Wild

• Google: Hackers Used AI to Develop Zero-Day Exploit for Web

View all
#Zero Trust13 articles

• Your Next Breach Will Look Like Business as Usual

• Cybersecurity Evolution: From Perimeter Defense to AI-Native Security

• Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense

View all
#cPanel13 articles

• cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug

• Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now

• Critical cPanel Flaw Mass-Exploited in 'Sorry' Ransomware

View all
#DNS13 articles

• Microsoft Patches 138 Vulnerabilities Including DNS and Netlogon RCE Flaws

• 'Underminr' Vulnerability Lets Attackers Hide Malicious

• Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

View all
#CMS13 articles

• Drupal Patches Highly Critical Vulnerability Exposing

• CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

• Australia Warns of Global Campaign Targeting Vulnerable CMS Platforms

View all
#CWE-7813 articles

• CVE-2021-4473: Tianxin Behavior Management System

• CVE-2026-0596: MLflow Command Injection via Unsanitized

• CVE-2026-12486: GeoVision GV-I/O Box 4E OS Command Injection via libNetSetObj.so

View all
#Weekly Recap12 articles

• Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach

• Weekly Recap: CI/CD Backdoor, FBI Buys Location Data

• Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple

View all
#General12 articles

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• Weekly Recap: CI/CD Backdoor, FBI Buys Location Data

• Anti-Piracy Coalition Takes Down AnimePlay App with 5

View all
#Cryptography12 articles

• Google Slashes Quantum Resource Requirements for Breaking

• Apple Open-Sources Quantum-Resistant Encryption Code

• Security Roundup: OpenAI Open Sources Codex Security CLI, AWS Pins NPM Attacks on North Korea, Anthropic Mythos Cracks Crypto

View all
#Router Security12 articles

• Authorities Disrupt APT28 Router DNS Hijacks Targeting

• ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI

• Acer Working to Patch Max Severity Zero-Days in Wave 7 Routers

View all
#NGINX12 articles

• Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables

• 18-Year-Old NGINX Rewrite Module Flaw Enables

• 18-Year-Old NGINX Vulnerability Allows DoS and Potential RCE

View all
#authentication12 articles

• cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug

• Chinese Hackers Hijack Auth Flow, Spy on Isolated Network for a Decade

• Critical Keycloak Flaw Lets Attackers Reset Any Account Password Without Authentication

View all
#Ubiquiti12 articles

• Ubiquiti Patches Three Max-Severity UniFi OS Vulnerabilities

• UniFi OS Command Injection via Improper Input Validation

• UniFi OS Improper Access Control — Unauthorized System

View all
#TLS12 articles

• HollowByte: 11-Byte Payload Triggers Memory Bloat DoS on OpenSSL Servers

• Google Begins Post-Quantum Cryptography Rollout Across

• CVE-2026-35560: Amazon Athena ODBC Driver Fails Certificate

View all
#Hardening12 articles

• Named Pipes Under Attack: Securing Windows Interprocess Communication

• Lynis: Linux Security Auditing and Hardening in Practice

• Nginx + ModSecurity WAF: Protecting Web Apps with OWASP CRS

View all
#Information Disclosure12 articles

• CVE-2016-20030: ZKTeco ZKBioSecurity 3.0 Username

• CVE-2025-47813: Wing FTP Server Path Disclosure Enables RCE

• CVE-2026-33669: SiYuan Unauthenticated Document Content

View all
#Database12 articles

• CVE-2018-25362: Twitter-Clone SQL Injection via follow.php

• CVE-2024-46636: NASA EOSDIS MODAPS v8.1 SQL Injection

• CVE-2026-11334: SQL Injection in College Management System

View all
#Tenda12 articles

• CVE-2024-51311: Critical Stack Overflow in Tenda TX9 Router Firmware

• CVE-2026-38577: Tenda HG21 Hardcoded Admin Credentials

• Tenda A15 UploadCfg Stack Buffer Overflow (CVE-2026-4567)

View all
#High12 articles

• CVE-2025-2749: Kentico Xperience Path Traversal

• CVE-2025-43510: Apple Multiple Products Improper Locking

• CVE-2026-10167: School Student Management System Cookie Auth Bypass

View all
#Totolink12 articles

• CVE-2026-10187: Totolink N300RH Stack Buffer Overflow in WiFi Config

• CVE-2026-31027: TOTOlink A3600R Buffer Overflow in setAppEasyWizardConfig

• CVE-2026-36841: TOTOLINK N200RE V5 Command Injection

View all
#Enterprise11 articles

• HellCat Ransomware Group Breaches Ascom, Exfiltrates 44GB

• Microsoft Shares Fix for Windows C: Drive Access Issues on Samsung PCs

• Microsoft Halts Forced Global Rollout of Microsoft 365

View all
#Japan11 articles

• Japanese Semiconductor Giant Advantest Hit by Ransomware

• Mazda Discloses Security Breach Exposing Employee and Partner Data

• Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

View all
#RaaS11 articles

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

• Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak

• Who Runs the Ransomware Group 'The Gentlemen'?

View all
#ChatGPT11 articles

• OpenAI Says ChatGPT Ads Are Not Rolling Out Globally For Now

• In Other News: ChatGPT Data Leak, Android Rootkit, Water

• ChatGPT Rolls Out New $100 Pro Subscription to Challenge

View all
#Startup11 articles

• Cloud Security Startup Native Exits Stealth With $42

• Eclypsium Raises $25 Million to Expand Device Supply Chain

• Socket Raises $60 Million at $1 Billion Valuation

View all
#France11 articles

• Cegedim Santé Breach Exposes 15.8 Million French Healthcare

• Elon Musk Fails to Appear for Questioning by French Police

• French Government Agency France Titres Confirms Data Breach

View all
#Worm11 articles

• Trivy Hack Spreads Infostealer via Docker, Triggers Worm

• Mini Shai-Hulud Worm Compromises TanStack, Mistral AI

• Worm Redux: Fresh Mini Shai-Hulud Infections Bite npm

View all
#The Record11 articles

• Supply Chain Attack Hits Widely-Used AI Package, Risking

• Dutch Court Threatens xAI with Fines Over Grok's

• European Parliament Rejects Extension of CSAM Scanning

View all
#Use-After-Free11 articles

• Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in 2026

• New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation

• Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

View all
#smb11 articles

• 6-Year Ransomware Campaign Targets Turkish Homes and SMBs

• CVE-2026-4149: Sonos Era 300 Unauthenticated RCE via SMB

• Why Every Business Needs Cyber Insurance in 2026

View all
#Hugging Face11 articles

• Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

• Fake OpenAI Repository on Hugging Face Pushes Infostealer

• Hugging Face Warns an Autonomous AI Agent Hacked Its Network

View all
#SOC11 articles

• In Other News: Scattered Spider Member Arrested, SOC

• One Missed Threat Per Week: What 25M Alerts Reveal About

• Exaforce Raises $125 Million for Agentic SOC Platform

View all
#Ivanti11 articles

• CISA Gives Federal Agencies Four Days to Patch Actively

• Ivanti Customers Confront Yet Another Actively Exploited

• Ivanti Warns of New EPMM Flaw Exploited in Zero-Day Attacks

View all
#UK11 articles

• UK Water Utility Fined £963,900 After Cl0p Lurked

• UK Fines Water Supplier $1.3M for Exposing Data of 664K

• GCHQ Chief: AI Is an 'Unstoppable Force' with Offensive and Defensive Cyber Ramifications

View all
#Memory Corruption11 articles

• New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

• Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

• CVE-2025-43510: Apple Multiple Products Improper Locking

View all
#UniFi11 articles

• Ubiquiti Patches Three Max-Severity UniFi OS Vulnerabilities

• Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

• CVE-2026-34909 — UniFi OS Path Traversal Leading to Account

View all
#AI Agents11 articles

• Security of 100 AI Agents Tested and Ranked – What You Need to Know

• Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

• Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

View all
#Joomla11 articles

• CISA Orders Feds to Patch Max Severity Joomla Plugin Flaw by Friday

• CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

• CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions

View all
#Session Hijacking11 articles

• New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

• NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

• JSCeal Malware Hijacks Google Sessions via Stolen Cookies

View all
#Authentication11 articles

• Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

• Password Spraying Attacks Surge 155x as Hackers Exploit MFA Gaps

• WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins

View all
#Vulnerability Research10 articles

• Google: 90 Zero-Days Exploited in 2025 — Enterprise Tech

• Black Hat USA 2026: What to Expect from the Year''s Biggest

• GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables

View all
#Money Laundering10 articles

• Spanish-Ukrainian Police Bust Gambling Ring That Exploited

• US Sentences Nigerian National to 7 Years in $6 Million

• Money Launderer for Crypto Thieves Given 5-Year Prison

View all
#Vulnerability Management10 articles

• The Zero-Day Scramble Is Avoidable: Why Attack Surface

• 1 Billion CISA KEV Records Reveal Human-Scale Security Has

• Analysis of 216M Security Findings Shows a 4x Increase in Critical Risk (2026 Report)

View all
#Actively Exploited10 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• Recent Apache ActiveMQ Vulnerability Exploited in the Wild

• Adobe Patches Actively Exploited Zero-Day That Lingered for Months

View all
#Qilin10 articles

• Malaysia Airlines Listed by Qilin Ransomware Group

• Die Linke German Political Party Confirms Data Stolen by Qilin Ransomware

• CISA Gives Feds 3 Days to Patch Check Point VPN Bug Exploited as Zero-Day

View all
#BEC10 articles

• US Sentences Nigerian National to 7 Years in $6 Million

• FBI: Americans Lost a Record $21 Billion to Cybercrime Last

• FBI: Cybercrime Losses Neared $21 Billion in 2025

View all
#Magento10 articles

• PolyShell Attacks Target 56% of All Vulnerable Magento

• WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

• Hackers Use Pixel-Large SVG Trick to Hide Credit Card

View all
#Encryption10 articles

• European Parliament Rejects Extension of CSAM Scanning

• Broken VECT 2.0 Ransomware Acts as a Data Wiper for Large

• In Other News: Big Tech vs Canada Encryption Bill, Cisco's

View all
#Data Protection10 articles

• Italian Regulator Fines Financial Giant $36 Million for Data Protection Failures

• Italian Regulator Fines National Postal Service Orgs $15

• Coupang Hit with Record $409 Million Data Breach Fine in South Korea

View all
#Regulation10 articles

• Italian Regulator Fines Financial Giant $36 Million for Data Protection Failures

• European Commission Accuses Meta of Breaching Child Safety

• UK to Require Government ID or Face Scan Before Creating Social Media Accounts

View all
#Supply Chain Security10 articles

• The State of Secrets Sprawl 2026: 9 Takeaways for CISOs

• OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds

• New Initiative Tackles Security for End-of-Life Open Source Software

View all
#LLM10 articles

• Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple

• Claude Fable 5 Isn't Permanently Leaving Subscriptions, Anthropic Says

• Claude Fable Relaunch Disappoints Users With Nerfed Performance

View all
#RAT10 articles

• Attack on Axios Developer Tool Threatens Widespread

• Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

• CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

View all
#Next.js10 articles

• Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts

• Hackers Exploit React2Shell in Automated Credential Theft

• Next.js Creator Vercel Hacked

View all
#SharePoint10 articles

• Microsoft Drops Its Second-Largest Monthly Patch Batch on Record

• Microsoft Issues Patches for SharePoint Zero-Day and 168

• Over 1,300 Microsoft SharePoint Servers Vulnerable to Ongoing Spoofing Attacks

View all
#Vercel10 articles

• Vercel Confirms Breach as Hackers Claim to Be Selling

• Next.js Creator Vercel Hacked

• Vercel Breach Tied to Context AI Hack Exposes Limited

View all
#Entra ID10 articles

• Microsoft to Roll Out Entra Passkeys on Windows in Late

• ConsentFix v3 Automates Azure OAuth Abuse With Mass

• Breach at the Beach: Play the Ultimate Entra ID CTF

View all
#SAP10 articles

• SAP-Related npm Packages Compromised in Credential-Stealing

• TeamPCP Hits SAP npm Packages With 'Mini Shai-Hulud' Supply

• 1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, and Intercom

View all
#TanStack10 articles

• Mini Shai-Hulud Worm Compromises TanStack, Mistral AI

• Worm Redux: Fresh Mini Shai-Hulud Infections Bite npm

• OpenAI Asks macOS Users to Update After TanStack npm Supply

View all
#Manufacturing10 articles

• West Pharmaceutical Services Hit by Disruptive Ransomware

• West Pharmaceutical Warns of Ransomware Attack Impacting

• Foxconn Confirms Cyberattack Claimed by Nitrogen Ransomware

View all
#Red Hat10 articles

• IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under "Project Lightwell"

• Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

• CVE-2026-10059: Multicluster Engine ClusterCurator Token Escalation (CVSS 9.1)

View all
#SSH10 articles

• Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

• Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

• CVE-2025-15638: Net::Dropbear Bundles Vulnerable

View all
#Missing Authorization10 articles

• CVE-2018-25391: HaPe PKH 1.1 Unauthenticated Record Deletion via Missing Authorization

• CVE-2025-10656: WooCommerce Plugin Missing Authorization Allows Unauthenticated Admin Account Creation

• Critical RCE in Hitachi Vantara Pentaho via Unrestricted

View all
#Plugin10 articles

• CVE-2025-12886: Oxygen Theme SSRF Allows Unauthenticated

• CVE-2026-13439: WordPress Easy Form Builder Unauthenticated Privilege Escalation (CVSS 9.8)

• CVE-2026-14545: TrueBooker WordPress Plugin Lets Anyone Take Over Admin Accounts

View all
#Dell10 articles

• CVE-2025-36568: Dell PowerProtect Data Domain BoostFS

• CVE-2026-35155: Dell iDRAC10 Race Condition Enables

• Dell ECS and ObjectScale: Hard-Coded Credentials

View all
#OpenClaw9 articles

• Cline CLI Supply Chain Attack Installs Unauthorized

• OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click

• More Malicious OpenClaw Skills Threaten AI Supply Chain

View all
#n8n9 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

View all
#DevOps9 articles

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

• Microsoft Hit by Back-to-Back Outages: M365 Admin Center

• CVE-2026-30836: Step CA SCEP UpdateReq Allows

View all
#canada9 articles

• Telus Digital Confirms Massive Breach After ShinyHunters

• In Other News: Big Tech vs Canada Encryption Bill, Cisco's

• Alleged Kimwolf Botmaster ''Dort'' Arrested, Charged in U.S. and Canada

View all
#Data Exfiltration9 articles

• OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click

• AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable

• Trigona Ransomware Deploys Custom CLI Exfiltration Tool in Active Attacks

View all
#Zimbra9 articles

• CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC

• Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks

• Zimbra Urges Customers to Patch Critical Web Client XSS Flaw Exploited in the Wild

View all
#Dark Reading9 articles

• Trivy Supply Chain Attack Targets CI/CD Secrets

• Blast Radius of TeamPCP Attacks Expands Amid Hacker

• 6-Year Ransomware Campaign Targets Turkish Homes and SMBs

View all
#Exploit9 articles

• AI Slashes Cyberattack Exploit Timelines From Years to Days

• New Linux 'Dirty Frag' Zero-Day Gives Root on All Major

• Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

View all
#Source Code9 articles

• Cisco Source Code Stolen in Trivy-Linked Dev Environment

• Trellix Confirms Source Code Breach With Unauthorized

• Trellix Source Code Breach Claimed by RansomHouse Hackers

View all
#Physical Security9 articles

• Adversaries Exploit Vacant Homes to Intercept Mail in Hybrid Cybercrime

• Ransomware Actors Show Up In Person to Steal Law Firm Data

• Japanese Energy Firm Loses Drive with Data of 10.9 Million Clients

View all
#Patient Data9 articles

• 250,000 Affected by Data Breach at Nacogdoches Memorial

• Medtronic Confirms Breach After Hackers Claim 9 Million

• Medtronic Hack Confirmed After ShinyHunters Threatens Data

View all
#KrebsOnSecurity9 articles

• Feds Disrupt IoT Botnets Behind Huge DDoS Attacks

• Germany Doxes "UNKN," Head of RU Ransomware Gangs REvil

• Microsoft Patch Tuesday, March 2026 Edition

View all
#Backup9 articles

• NAKIVO v11.2: Ransomware Defense, Faster Replication

• New Veeam Vulnerability Exposes Backup Servers to RCE Attacks

• Veeam Backup and Replication RCE Flaw Lets Domain Users Run Remote Code

View all
#Identity9 articles

• Microsoft to Roll Out Entra Passkeys on Windows in Late

• Tycoon2FA Hijacks Microsoft 365 Accounts via Device-Code

• Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

View all
#Retail9 articles

• New BlackFile Extortion Group Linked to Surge of Vishing

• Zara Data Breach Exposed Personal Information of 197,000

• 7-Eleven Data Breach Confirmed After ShinyHunters Ransom

View all
#SEC Disclosure9 articles

• American Utility Firm Itron Discloses Breach of Internal IT

• West Pharmaceutical Warns of Ransomware Attack Impacting

• Coca-Cola Fairlife Ransomware Attack Halts All US Dairy Production

View all
#Personal Data9 articles

• Home Security Giant ADT Data Breach Affects 5.5 Million

• DocketWise Data Breach Impacts 143,000 Individuals

• IMA Diligence Services Data Breach Impacts 525,000 People

View all
#Sentencing9 articles

• Money Launderer for Crypto Thieves Given 5-Year Prison

• Former Incident Responders Sentenced to 4 Years for Ransomware Attacks on Clients

• Cyber Incident Responders Sentenced to 4 Years for Carrying

View all
#LMS9 articles

• Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

• Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

• KnowledgeDeliver Flaw Exploited as Zero-Day to Install Web

View all
#Web Server9 articles

• 18-Year-Old NGINX Rewrite Module Flaw Enables

• 18-Year-Old NGINX Vulnerability Allows DoS and Potential RCE

• PoC Code Published for Critical NGINX Vulnerability

View all
#DoS9 articles

• 18-Year-Old NGINX Vulnerability Allows DoS and Potential RCE

• Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

• HollowByte: 11-Byte Payload Triggers Memory Bloat DoS on OpenSSL Servers

View all
#Exploitation9 articles

• NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker

• Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

• WP Maps Pro Bug Exploited to Create Admin Accounts on WordPress Sites

View all
#Grafana9 articles

• Grafana Confirms Breach After Hackers Claim They Stole Data

• Grafana Says Stolen GitHub Token Let Hackers Steal Codebase

• Grafana Breach Caused by Missed Token Rotation After

View all
#IDOR9 articles

• Data Exposure Flaws in Dify AI Platform Put 1 Million+ App Tenants at Risk

• Coolify CVE-2026-34037: CVSS 9.9 IDOR Enables Cross-Team Resource Takeover

• CVE-2026-25197: IDOR Flaw Lets Authenticated Users Access

View all
#AI Safety9 articles

• OpenAI Previews GPT-5.6 Sol Under Government-Gated Rollout with Stronger Cyber Safeguards

• Anthropic's Claude Breached 3 Orgs, Uploaded PyPI Malware During Tests

• Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

View all
#Hardcoded Credentials9 articles

• CVE-2016-20026: ZKTeco ZKBioSecurity 3.0 Hardcoded Tomcat

• CVE-2025-63823: My Safetipin Android App Exposes Hardcoded Credentials (CVSS 9.8)

• CVE-2026-11849: IRM-IEI Remote Management Hardcoded Credentials

View all
#Database Security9 articles

• CVE-2018-25272: ELBA5 5.8.0 RCE via Default Database

• CVE-2026-19001: MongoDB BI Connector ODBC Driver Buffer Overflow (CVSS 9.8)

• CVE-2026-24013: Apache IoTDB Authentication Bypass via Forged Session ID

View all
#REST API9 articles

• CVE-2021-47933: WordPress MStore API 2.0.6 Arbitrary File

• CVE-2026-15162: WordPress Object Sync for Salesforce — SQLi via REST API

• CVE-2026-16149: Security Hardener WordPress Plugin Bypasses All REST API Authorization

View all
#code-projects9 articles

• CVE-2026-10178: SQL Injection in Online Music Site 1.0 Admin Panel

• CVE-2026-5017: SQL Injection in code-projects Simple Food

• CVE-2026-5018: SQL Injection in code-projects Simple Food

View all
#CVSS 9.19 articles

• CVE-2026-15265: Tenable Agent Path Traversal — Arbitrary File Write & RCE (CVSS 9.1)

• CVE-2026-26026: GLPI Template Injection Enables

• CVE-2026-31986: Apache OFBiz Hard-Coded Cryptographic Key

View all
#Financial Crime8 articles

• FBI Warns of ATM Jackpotting Surge as Losses Top $20

• Cryptocurrency ATM Giant Bitcoin Depot Reports $3.6 Million

• Cybercriminals Target Accountants to Drain Russian Firms'

View all
#APT288 articles

• APT28 Operation MacroMaze: Russia-Linked Hackers Hit

• Authorities Disrupt APT28 Router DNS Hijacks Targeting

• APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine

View all
#Infrastructure8 articles

• The World's First Transatlantic Fiber Cable Is Being Pulled

• Police Seize 'First VPN' Service Used in Ransomware and Data Theft Attacks

• DeadLock Ransomware Uses Blockchain to Resist Infrastructure Takedown

View all
#Web Application Security8 articles

• LexisNexis Confirms Cloud Breach Exposing 400K User

• Hackers Exploit React2Shell in Automated Credential Theft

• CVE-2026-13550: SQL Injection in itsourcecode Baptism Information Management System 1.0

View all
#Spyware8 articles

• Google: 90 Zero-Days Exploited in 2025 — Enterprise Tech

• DarkSword GitHub Leak Threatens to Turn Elite iPhone

• Bulgaria Allowed Surveillance Tech Firm to Sell Products to Repressive Regimes, Report Says

View all
#PHI8 articles

• Cognizant TriZetto Breach Exposes Health Data of 3.4

• Hims & Hers Breach Exposes the Most Sensitive Kinds of Patient PHI

• 716,000 Impacted by OpenLoop Health Data Breach

View all
#Veeam8 articles

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

• New Veeam Vulnerability Exposes Backup Servers to RCE Attacks

• Veeam Backup and Replication RCE Flaw Lets Domain Users Run Remote Code

View all
#Cyberattack8 articles

• Stryker Cyberattack Wiped Tens of Thousands of Devices — No

• Moldova's Health Insurance Agency Reports Possible Data

• Cyberattack on Russian Tech Firm Astral Disrupts Business and Government Services for a Week

View all
#Automotive8 articles

• Mazda Discloses Security Breach Exposing Employee and Partner Data

• Nissan Says Stolen Data Came from Third-Party Vendor After

• GM to Pay Over $12 Million in Largest-Ever CCPA Fine Over

View all
#LiteLLM8 articles

• Supply Chain Attack Hits Widely-Used AI Package, Risking

• Mercor Confirms Security Incident Tied to LiteLLM Supply

• The Good, the Bad and the Ugly in Cybersecurity – Week 14

View all
#WebSocket8 articles

• New RoadK1ll WebSocket Implant Used to Pivot on Breached

• Coolify CVE-2026-34047: Terminal WebSocket Authorization Bypass (CVSS 9.9)

• Coolify CVE-2026-34048: Low-Privilege Terminal Escalation via WebSocket (CVSS 9.9)

View all
#Claude Code8 articles

• Claude Code Source Code Accidentally Leaked in NPM Package

• Claude Code Leak Used to Push Infostealer Malware on GitHub

• Critical Vulnerability in Claude Code Emerges Days After

View all
#Weekly Roundup8 articles

• ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache

• In Other News: Satellite Cybersecurity Act, $90K Chrome

• ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force

View all
#Meta8 articles

• European Commission Accuses Meta of Breaching Child Safety

• Hackers Used Meta's AI Support Bot to Seize Instagram Accounts

• WhatsApp Is Finally Getting Usernames to Help Keep Phone Numbers Private

View all
#Apache8 articles

• Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS

• AI-Assisted HTTP Terminator Finds Novel Desync Techniques and Apache Zero-Day

• CVE-2025-55017: Apache IoTDB Critical Path Traversal Vulnerability

View all
#Web Shell8 articles

• Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

• KnowledgeDeliver Flaw Exploited as Zero-Day to Install Web

• KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

View all
#Machine Learning8 articles

• Frontier AI Reinforces the Future of Modern Cyber Defense

• Claude Fable 5 Stays Free for Paid Users Until July 19 as Anthropic Buys More Time

• OpenAI Temporarily Relaxes GPT-5.6 Sol Usage Limits Amid Demand Surge

View all
#Unauthenticated RCE8 articles

• Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

• CVE-2026-1579: MAVLink Protocol Unauthenticated Shell Access

• CVE-2026-27053: Critical PHP Object Injection in Broadcast Live Video Plugin

View all
#PHP Object Injection8 articles

• Critical GiveWP Flaw Lets Hackers Run Server Commands

• CVE-2026-14637: PHP Deserialization RCE in CodeIgniter Ecommerce Bootstrap Shopping Cart

• CVE-2026-15962: PHP Object Injection in Fluent Forms Pro (CVSS 8.8)

View all
#JWT8 articles

• CVE-2025-57735: Apache Airflow JWT Token Not Invalidated on Logout

• CVE-2026-1114: lollms JWT Weak Secret Key Allows Admin

• MStore API Plugin: Unauthenticated JWT Forgery Auth Bypass

View all
#Heap Buffer Overflow8 articles

• CVE-2026-19874: Critical Heap Buffer Overflow in Metal Gear Online 3

• CVE-2026-20889: LibRaw x3f_thumb_loader Heap Buffer

• CVE-2026-20911: LibRaw HuffTable::initval Heap Buffer

View all
#Networking8 articles

• CVE-2026-40621: ELECOM Wireless LAN Access Point

• CrowdSec: Deploy a Community-Powered Intrusion Prevention System

• How to Set Up BGP Monitoring and Route Alerts

View all
#IP Camera8 articles

• GeoVision LPC Camera Critical RCE via thttpd Buffer Overflow (CVE-2026-57878)

• GeoVision LPC Camera Critical RCE via ssvr RTSP Auth Buffer Overflow (CVE-2026-57879)

• GeoVision LPC Camera Critical RCE via ssvr RTSP Digest Auth Buffer Overflow (CVE-2026-57880)

View all
#CIS Benchmarks8 articles

• FortiGate Security Hardening: Best Practices for Enterprise

• Windows Server Hardening: A Complete Security Guide for Enterprises

• AWS Security Hub: Centralized Security Findings

View all
#Monitoring8 articles

• How to Set Up BGP Monitoring and Route Alerts

• Network Monitoring Basics: Detect Threats Before They Spread

• Build a Production Monitoring Stack with Prometheus and Grafana

View all
#EU7 articles

• Google's $32 Billion Wiz Acquisition Clears Final Hurdle as

• CERT-EU: European Commission Hack Exposes Data of 30 EU

• DORA and Operational Resilience: Credential Management as a

View all
#Deepfake7 articles

• ShinyHunters Dumps Harvard and UPenn Data After Ransom

• Deepfake Voice Attacks Are Outpacing Defenses: What

• Weaponized AI: The New Frontier of Fraud and Identity

View all
#Surveillance7 articles

• Persona Source Code Leak Exposes Hidden Biometric

• Citizen Lab: Law Enforcement Used Webloc to Track 500

• Bulgaria Allowed Surveillance Tech Firm to Sell Products to Repressive Regimes, Report Says

View all
#Developer Tools7 articles

• Cline CLI Supply Chain Attack Installs Unauthorized

• Microsoft Suspends Dev Accounts for High-Profile Open

• Critical Gemini CLI Flaw Enabled Host Code Execution

View all
#CrowdStrike7 articles

• CrowdStrike 2026 Threat Report: eCrime Breakout Time Falls

• CrowdStrike Dismantles Glassworm Botnet Targeting Open-Source Supply Chain

• GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

View all
#MFA Bypass7 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Why Simple Breach Monitoring Is No Longer Enough

• Tycoon2FA Hijacks Microsoft 365 Accounts via Device-Code

View all
#Windows 117 articles

• Windows 11 February Update Breaks C:\ Drive Access on Samsung PCs

• Microsoft Now Force-Upgrades Unmanaged Windows 11 24H2 PCs

• Microsoft Rolls Out Revamped Windows Insider Program

View all
#Samsung7 articles

• Windows 11 February Update Breaks C:\ Drive Access on Samsung PCs

• Microsoft Shares Fix for Windows C: Drive Access Issues on Samsung PCs

• CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal

View all
#Interpol7 articles

• Operation Synergia III: Police Sinkhole 45,000 IPs in Global Cybercrime Crackdown

• INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific

• Ransomware Thugs Masquerade as Interpol to Entice Small Biz

View all
#AI Regulation7 articles

• Dutch Court Threatens xAI with Fines Over Grok's

• UK Government Threatens Tech Bosses With Jail Time Over AI

• Elon Musk Fails to Appear for Questioning by French Police

View all
#Axios7 articles

• Attack on Axios Developer Tool Threatens Widespread

• Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

• Axios NPM Package Breached in North Korean Supply Chain

View all
#Lazarus Group7 articles

• Drift Crypto Platform Confirms $280 Million Stolen as

• KelpDAO Suffers $290 Million Heist Tied to Lazarus Hackers

• Crypto Infrastructure Company Blames $290 Million Theft on North Korean Hackers

View all
#Risk Management7 articles

• The Hidden Cost of Recurring Credential Incidents

• One Missed Threat Per Week: What 25M Alerts Reveal About

• Why Chargebacks Are Just One Piece of the Fraud Puzzle

View all
#AI Policy7 articles

• Commerce Setting Up New AI Export Regime to Push Adoption

• Anthropic Disables Fable 5 and Mythos 5 After U.S. Government Export Control Decree

• Anthropic Confirms Fable 5 and Mythos 5 Offline to Comply With US Export Controls

View all
#Microsoft Edge7 articles

• Microsoft Teams Right-Click Paste Broken by Edge Update Bug

• ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days

• Google and Microsoft Pull ModHeader After Hidden Tracker Found in 1.6M-Install Extension

View all
#Windows Server7 articles

• Microsoft Releases Emergency Updates to Fix Windows Server

• Microsoft: Domain Controller Lookup May Fail on Windows

• Microsoft June 2026 Updates Break Recycle Bin Confirmation Prompts on All Windows Versions

View all
#Regulatory Fine7 articles

• Italian Regulator Fines National Postal Service Orgs $15

• UK Fines Water Supplier $1.3M for Exposing Data of 664K

• Coupang Hit with Record $409 Million Data Breach Fine in South Korea

View all
#C27 articles

• Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

• 'Underminr' Vulnerability Lets Attackers Hide Malicious

• Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

View all
#Web Hosting7 articles

• cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug

• Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now

• Critical cPanel Flaw Mass-Exploited in 'Sorry' Ransomware

View all
#LLM Security7 articles

• Ollama Out-of-Bounds Read Flaw Allows Remote Process Memory

• New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

• JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware

View all
#PAN-OS7 articles

• PAN-OS RCE Exploit Under Active Use Enabling Root Access

• ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI

• Palo Alto GlobalProtect VPN Auth Bypass Flaw Now Exploited in Attacks

View all
#South Korea7 articles

• Can Laws Stop Deepfakes? South Korea Aims to Find Out

• Coupang Hit with Record $409 Million Data Breach Fine in South Korea

• South Korea Discloses Data Breach Impacting Diplomats Worldwide

View all
#Self-Hosted7 articles

• Gitea Vulnerability Exposes Private Container Images without Authentication

• Hackers Exploit Critical Auth Bypass in Official Gitea Docker Image

• Coolify CVE-2026-34037: CVSS 9.9 IDOR Enables Cross-Team Resource Takeover

View all
#Brute Force7 articles

• Dashlane Password Manager Users Locked Out by Brute Force Attacks

• Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

• Dashlane Discloses Brute-Force Attack: Encrypted Vaults of Fewer Than 20 Users Downloaded

View all
#Threat Detection7 articles

• Only 10% of SOCs Say They're Getting Excellent Value From AI — What the Second Wave Must Deliver

• How to Deploy Falco for Kubernetes Runtime Security

• How to Deploy Wazuh SIEM/XDR for Unified Security Monitoring

View all
#WhatsApp7 articles

• WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs

• WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

• Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

View all
#Google Chrome7 articles

• Google and Microsoft Pull ModHeader After Hidden Tracker Found in 1.6M-Install Extension

• Chrome Web Store Extensions Caught Stealing Crypto, Browser Data

• Google Chrome Critical Update Patches High-Severity Code

View all
#MFA7 articles

• Identity Attacks Overtake Exploits as Top Ransomware Cause

• Password Spraying Attacks Surge 155x as Hackers Exploit MFA Gaps

• WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins

View all
#ColdFusion7 articles

• Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic

• Adobe's September 2026 Patch Tuesday Fixes 170+ Flaws Across Experience Manager, ColdFusion & More

• CVE-2026-47928: Adobe ColdFusion Critical RCE — CVSS 9.6

View all
#GeoVision7 articles

• CVE-2026-12485: GeoVision GV-I/O Box 4E UDP Stack Overflow (IP Address Field)

• CVE-2026-12486: GeoVision GV-I/O Box 4E OS Command Injection via libNetSetObj.so

• CVE-2026-12846: GeoVision GV-I/O Box 4E UDP Stack Overflow (Net Mask Field)

View all
#CWE-947 articles

• CVE-2026-12866: expr-eval npm Package Enables Arbitrary Code Execution via toJSFunction()

• CVE-2026-1540: Spam Protect CF7 WordPress Plugin PHP Log RCE

• CVE-2026-22679: Weaver E-cology 10.0 Unauthenticated Remote

View all
#Traefik7 articles

• CVE-2026-35051: Traefik ForwardAuth Authentication Bypass

• CVE-2026-39858: Traefik Forwarded-Header Sanitization

• Multi-Stack Docker Infrastructure with Traefik and Authentik

View all
#Geopolitics6 articles

• WEF Global Cybersecurity Outlook 2026 Warns of 'Permanent

• Pro-Russian Hacktivists Launch Sustained Cyber Campaign

• Commerce Setting Up New AI Export Regime to Push Adoption

View all
#Vishing6 articles

• ShinyHunters Dumps Harvard and UPenn Data After Ransom

• New BlackFile Extortion Group Linked to Surge of Vishing

• Deepfake Voice Attacks Are Outpacing Defenses: What

View all
#DeepSeek6 articles

• Anthropic Exposes Industrial-Scale AI Distillation Attacks

• AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android

• Chinese Threat Actor Uses DeepSeek and Hermes Agent to Launch Fully Autonomous Cyberattacks

View all
#Europe6 articles

• APT28 Operation MacroMaze: Russia-Linked Hackers Hit

• Italian Regulator Fines Financial Giant $36 Million for Data Protection Failures

• Europe Evolves Into Ransomware's Favorite Region

View all
#Sanctions6 articles

• U.S. Treasury Sanctions Russian Zero-Day Broker Operation

• Russian Spies Aggressively Targeting Western Technology as Sanctions Bite

• The U.S. Sanctions Nobitex Crypto Exchange Used by Ransomware

View all
#BlackCat6 articles

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

• Former Ransomware Negotiator Pleads Guilty to BlackCat

• US Ransomware Negotiators Get 4 Years in Prison Over

View all
#Workflow Automation6 articles

• CISA Flags Actively Exploited n8n RCE Bug as 24,700

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

View all
#Federal6 articles

• CISA Orders Federal Agencies to Patch n8n RCE Flaw

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• CISA Gives Federal Agencies Four Days to Patch Actively

View all
#Backup & Replication6 articles

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

• Veeam Backup & Replication Auth RCE — CVE-2026-21666

• Veeam Backup & Replication 2nd Auth RCE — CVE-2026-21667

View all
#Enterprise Backup6 articles

• Veeam Patches Five Critical RCE Vulnerabilities Exposing

• Veeam Backup & Replication Auth RCE — CVE-2026-21666

• Veeam Backup & Replication 2nd Auth RCE — CVE-2026-21667

View all
#VS Code6 articles

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

• Malicious KICS Docker Images and VS Code Extensions Hit

• GitHub Links Repo Breach to TanStack npm Supply-Chain Attack

View all
#Shadow AI6 articles

• Shadow AI Is Everywhere. Here's How to Find and Secure It.

• Learning from the Vercel Breach: Shadow AI and OAuth Sprawl

• 5 Steps to Managing Shadow AI Tools Without Slowing Down

View all
#SaaS Security6 articles

• Shadow AI Is Everywhere. Here's How to Find and Secure It.

• Shadow AI in SaaS: How Hidden AI Agents Are Enabling

• Video Service Vimeo Confirms Anodot Breach Exposed User Data

View all
#Citrix6 articles

• Citrix Urges Admins to Patch NetScaler Flaws as Soon as

• Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active

• Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks

View all
#Adobe Commerce6 articles

• PolyShell Attacks Target 56% of All Vulnerable Magento

• Hackers Exploit Critical Adobe Commerce Flaw to Hijack Customer Accounts

• 'StyleSmuggler' Zero-Day in Magento and Adobe Commerce Is Actively Backdooring Live Stores

View all
#F56 articles

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• Hackers Now Exploit Critical F5 BIG-IP Flaw in Attacks

• F5 BIG-IP Vulnerability Reclassified from DoS to RCE Under

View all
#BIG-IP6 articles

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• Hackers Now Exploit Critical F5 BIG-IP Flaw in Attacks

• F5 BIG-IP Vulnerability Reclassified from DoS to RCE Under

View all
#National Security6 articles

• FCC Bans Import of Foreign-Made Consumer Routers Over

• New U.S. Cyber Force Would Cost Up to $11 Billion to Start, Commission Says

• Anthropic Disables Fable 5 and Mythos 5 After U.S. Government Export Control Decree

View all
#Southeast Asia6 articles

• Three China-Linked Clusters Target Southeast Asian

• DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets

• Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown

View all
#Bitcoin6 articles

• Google Slashes Quantum Resource Requirements for Breaking

• Hackers Steal $3.6 Million from Crypto ATM Giant Bitcoin

• ShinyHunters Data Leaks Fuel $2,000 Sextortion Email Scam

View all
#Crypto6 articles

• Crypto Platform Drift Suspends Services After Hundreds of Millions Stolen

• Polymarket Customers Lose $3 Million in Supply-Chain Attack

• $3 Million Reportedly Stolen in Polymarket Hack

View all
#Pre-Auth6 articles

• New Progress ShareFile Flaws Can Be Chained in Pre-Auth RCE

• vBulletin Fixes Critical Pre-Auth RCE Flaw with Public Exploit

• BeyondTrust Remote Support Pre-Authentication RCE Under

View all
#Supply Chain Attack6 articles

• Axios npm Hack Used Fake Teams Error Fix to Hijack

• Suspicious Polyfill Login Prompts Pop Up on Toshiba, Muji Websites

• Polymarket Customers Lose $3 Million in Supply-Chain Attack

View all
#CyberScoop6 articles

• Trump Budget Proposal Would Cut Hundreds of Millions More

• Why the Axios Attack Proves AI Is Mandatory for Supply

• Former DigitalMint Ransomware Negotiator Pleads Guilty to $75.3M Extortion Scheme

View all
#NVIDIA6 articles

• GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables

• NVIDIA Confirms GeForce NOW Data Breach Affecting Armenian

• Microsoft, Tech Companies Throw Weight Behind Spread of Open-Source AI

View all
#Credentials6 articles

• The Hidden Cost of Recurring Credential Incidents

• DORA and Operational Resilience: Credential Management as a

• FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices

View all
#Patch Management6 articles

• 1 Billion CISA KEV Records Reveal Human-Scale Security Has

• 73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation

• CISA Orders Feds to Patch Max Severity Joomla Plugin Flaw by Friday

View all
#Export Controls6 articles

• Commerce Setting Up New AI Export Regime to Push Adoption

• Anthropic Disables Fable 5 and Mythos 5 After U.S. Government Export Control Decree

• Anthropic Confirms Fable 5 and Mythos 5 Offline to Comply With US Export Controls

View all
#Windows Defender6 articles

• Three Microsoft Defender Zero-Days Actively Exploited; Two

• Microsoft Warns of New Defender Zero-Days Exploited in Attacks

• Microsoft Warns of Two Actively Exploited Defender

View all
#Microsoft Teams6 articles

• Microsoft Teams Right-Click Paste Broken by Edge Update Bug

• Threat Actor Uses Microsoft Teams to Deploy New 'Snow'

• KongTuke Hackers Now Use Microsoft Teams for Corporate

View all
#Firefox6 articles

• Firefox Vulnerability Allows Tor User Fingerprinting Across

• Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities

• CVE-2026-5731: Firefox and Thunderbird Critical Memory

View all
#Child Safety6 articles

• European Commission Accuses Meta of Breaching Child Safety

• Canadian Man Gets 33 Years for Using Social Media to Coerce US Children

• Senators Press TikTok Over Withholding Safety Features from Users

View all
#MSP6 articles

• Top Five Sales Challenges Costing MSPs Cybersecurity Revenue

• Ransomware Protection for MSPs: A 6-Point Checklist for Faster Recovery

• CVE-2026-18577: N-able N-central Authentication Bypass and Account Takeover

View all
#EPMM6 articles

• CISA Gives Federal Agencies Four Days to Patch Actively

• Ivanti Customers Confront Yet Another Actively Exploited

• Ivanti Warns of New EPMM Flaw Exploited in Zero-Day Attacks

View all
#Kernel6 articles

• New Linux 'Dirty Frag' Zero-Day Gives Root on All Major

• Making Vulnerable Drivers Exploitable Without Hardware: The

• Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks

View all
#Palo Alto Networks6 articles

• PAN-OS RCE Exploit Under Active Use Enabling Root Access

• Palo Alto GlobalProtect VPN Auth Bypass Flaw Now Exploited in Attacks

• PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

View all
#Energy Sector6 articles

• China's 'FamousSparrow' APT Nests in South Caucasus Energy

• Japanese Energy Firm Loses Drive with Data of 10.9 Million Clients

• Origin Energy Data Breach Exposes Millions of Australian Customers

View all
#BitLocker6 articles

• Windows BitLocker Zero-Day Gives Access to Protected

• Researcher Drops YellowKey, GreenPlasma Windows Zero-Days

• Windows Zero-Days Expose BitLocker Bypasses and CTFMON

View all
#Heap Overflow6 articles

• 18-Year-Old NGINX Rewrite Module Flaw Enables

• CVE-2026-40492: SAIL XWD Codec Heap Buffer Overflow (CVSS

• CVE-2026-40494: SAIL TGA Codec RLE Decoder Asymmetric

View all
#PraisonAI6 articles

• PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours

• CVE-2026-39888: PraisonAI Sandbox Escape Enables Remote

• CVE-2026-39890: PraisonAI YAML Injection Achieves Remote

View all
#Vulnerability Disclosure6 articles

• Microsoft Rejects Critical Azure Vulnerability Report, No

• Microsoft Says Zero-Day Public Releases Are 'Never Justifiable' as Researcher Threatens More Drops

• Microsoft Says It Will Not Pursue Security Researchers After Zero-Day Backlash

View all
#Arrest6 articles

• ''First VPN'' Cybercrime Service Disrupted, Administrator

• Alleged Kimwolf Botmaster ''Dort'' Arrested, Charged in U.S. and Canada

• Canadian Man Arrested and Charged for Running KimWolf DDoS

View all
#Research6 articles

• Making Vulnerable Drivers Exploitable Without Hardware: The

• Security of 100 AI Agents Tested and Ranked – What You Need to Know

• Leak Confirms OpenAI Is Testing a ChatGPT for Science Subscription

View all
#Gitea6 articles

• Gitea Vulnerability Exposes Private Container Images without Authentication

• Hackers Exploit Critical Auth Bypass in Official Gitea Docker Image

• Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

View all
#Credential Stuffing6 articles

• Dashlane Password Manager Users Locked Out by Brute Force Attacks

• Minnesota Man Known as 'Snoopy' Sentenced in DraftKings Hack

• Chick-fil-A Discloses Data Breach After Credential Stuffing Attacks

View all
#Check Point6 articles

• CISA Gives Feds 3 Days to Patch Check Point VPN Bug Exploited as Zero-Day

• Check Point VPN Zero-Day Exploited Since Early May by Qilin Ransomware

• Check Point Patches SmartConsole Zero-Day Exploited in Attacks

View all
#Australia6 articles

• Australian Sugar Producer Works to Restore Operations After Ransomware Attack

• Origin Energy Data Breach Exposes Millions of Australian Customers

• Origin Energy Data Breach: Fired Employee's Credentials Expose Up to 2 Million Australian Customers

View all
#Secrets Management6 articles

• Novo Nordisk Breach Exposes Software Development Pipeline Risk

• SailPoint to Acquire Entro in Reported $200 Million Deal

• Lessons Learned from CISA's Recent GitHub Leak

View all
#Data Exposure6 articles

• Data Exposure Flaws in Dify AI Platform Put 1 Million+ App Tenants at Risk

• Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

• 9,300+ Leaked AWS Keys Still Active, Granting Full Corporate Account Control

View all
#Signal6 articles

• Russia Used Social Engineering to Breach Prominent Messaging Accounts, Ukraine Says

• Ukraine and FBI Expose Russian Intelligence Campaign Stealing Signal Credentials via Fake SMS

• FBI: Russian Hackers Now Target Signal Backup Recovery Keys

View all
#Telegram6 articles

• Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

• RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

• Hackers Hijack Russian Journalist Sobchak's Telegram Channels via Email Breach, Claim 350 GB Stolen

View all
#Load Balancer6 articles

• Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

• Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

• CVE-2026-47868: VMware Avi Load Balancer Local Privilege Escalation

View all
#Embedded Security6 articles

• 7 Unpatched Flaws Disclosed in FatFs Filesystem Used in Millions of Embedded Devices

• Flipper Zero Firmware Development Continues With Community Help

• Six U-Boot Flaws Could Enable Stealthy Firmware Attacks on Embedded Devices

View all
#threat-intelligence6 articles

• Chinese LLMs Broaden the Gap Between Attackers & Defenders

• China-Linked Storm-1175 Turns N-able N-central Into MSP Ransomware Launchpad

• Ransom Busters: Ransomware Affiliate Poses as Data Recovery Firm

View all
#supply-chain6 articles

• 'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat

• Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

• China-Linked Storm-1175 Turns N-able N-central Into MSP Ransomware Launchpad

View all
#GitLab6 articles

• Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

• Critical GitLab GraphQL Flaw Lets Unauthenticated Attackers Delete Public Projects

• CISA Adds Four Critical Vulnerabilities to KEV Catalog

View all
#Firewall6 articles

• Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

• The Network Has Become the Control Plane for AI Security

• FBI, South Korea Warn of Gunra Ransomware Gang Targeting Critical Infrastructure

View all
#CVSS 10.06 articles

• Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

• UniFi OS Improper Access Control — Unauthorized System

• CVE-2026-47131: vm2 Sandbox Escape via Buffer Prototype Hijack (CVSS 10.0)

View all
#Denial of Service6 articles

• Cisco Warns of ASA and FTD VPN Flaw Actively Exploited to Crash Firewalls

• CVE-2018-25169: Denial of Service Vulnerability Catalogued

• CVE-2026-20349: Cisco ASA and FTD Heap Inspection Vulnerability

View all
#Broadcom6 articles

• Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

• CVE-2026-47865: Critical Authentication Bypass in VMware Avi Load Balancer

• CVE-2026-47866: Authorization Bypass in VMware Avi Load Balancer

View all
#Cross-Site Scripting6 articles

• CVE-2015-20118: Stored XSS in RealtyScript 4.0.2 Admin

• CVE-2025-61311: Reflected XSS in docuForm Managed Print

• CVE-2026-10087: GitLab EE Stored XSS via Developer Role

View all
#Arbitrary File Write6 articles

• CVE-2025-15036: MLflow Path Traversal in Archive Extraction

• CVE-2026-14289: FacturaONE WooCommerce Plugin Allows Unauthenticated File Write

• CVE-2026-15265: Tenable Agent Path Traversal — Arbitrary File Write & RCE (CVSS 9.1)

View all
#SAML6 articles

• PicketLink SAML Authentication Bypass — Forged Assertions Accepted Without Validation

• CVE-2026-15013: WordPress SAML SSO Plugin — Algorithm Confusion Auth Bypass

• CVE-2026-15981: WordPress SAML SSO Authentication Bypass (CVSS 9.8)

View all
#CWE-2876 articles

• CVE-2026-12183: Critical Auth Bypass in Gas Station Automation System

• CVE-2026-12492: WooCommerce OTP Login Plugin Auth Bypass — Full Admin Takeover

• CVE-2026-14205: WP Events Manager Plugin Allows Fraudulent Paid Event Bookings via Payment Bypass

View all
#Directory Traversal6 articles

• CVE-2026-13339: CubeWP Framework WordPress Plugin Directory Traversal (CVSS 7.5)

• CVE-2026-18352: WordPress User Access Manager Directory Traversal

• CVE-2026-34909 — UniFi OS Path Traversal Leading to Account

View all
#Password Reset6 articles

• CVE-2026-13498: SQL Injection in Restaurant Management System via Password Reset

• CVE-2026-14364: TrueBooker WordPress Plugin Account Takeover via Password Reset Bypass

• CVE-2026-24467: OpenAEV Password Reset Account Takeover

View all
#File Deletion6 articles

• CVE-2026-14484: WordPress RapiSafe Plugin Arbitrary File Deletion

• CVE-2026-14487: WordPress Simple Coherent Form Plugin — Critical Unauthenticated File Deletion

• CVE-2026-14524: Critical Unauthenticated File Deletion in ProSolution WP Client

View all
#Arbitrary File Upload6 articles

• CVE-2026-14894: WordPress Super Forms Plugin Critical Arbitrary File Upload

• CVE-2026-15282: WordPress Instant Appointment Plugin Critical File Upload

• Critical File Upload RCE in Templatiq WordPress Plugin (CVE-2026-32474)

View all
#Wazuh6 articles

• CVE-2026-25769: Wazuh Critical RCE via Insecure

• CVE-2026-25770: Wazuh Privilege Escalation to Root via Cluster Protocol File Write

• CVE-2026-56699: Critical NDJSON Injection in Wazuh Manager (CVSS 10.0)

View all
#CVSS Critical6 articles

• CVE-2026-37431: Beauty Parlour Management System SQL

• CVE-2026-38158: Critical SQL Injection in UReport v2.2.9 (CVSS 9.8)

• CVE-2026-41583: ZEBRA Zcash Node Consensus Rule Bypass

View all
#vm26 articles

• CVE-2026-47131: vm2 Sandbox Escape via Buffer Prototype Hijack (CVSS 10.0)

• CVE-2026-47137: vm2 Sandbox Escape via Strict Equality require Bypass (CVSS 10.0)

• CVE-2026-47140: vm2 Sandbox Escape via Incomplete Builtin Denylist (CVSS 10.0)

View all
#Legal5 articles

• Ex-L3Harris Executive Pleads Guilty to Selling Eight

• LexisNexis Confirms Cloud Breach Exposing 400K User

• Microsoft's Zero-Day Legal Threats Spark Backlash

View all
#Data Extortion5 articles

• Ransomware in 2026: Data-Only Extortion Replaces Encryption

• Evolution of Ransomware: Multi-Extortion Ransomware Attacks

• Tata Electronics Confirms Cyberattack; World Leaks Exposes Apple Manufacturing IP

View all
#Scattered Spider5 articles

• Scattered Lapsus$ ShinyHunters Alliance Hits 100+

• In Other News: Scattered Spider Member Arrested, SOC

• Grafana Confirms Breach After Hackers Claim They Stole Data

View all
#Deepfakes5 articles

• AI-Driven Threats Accelerate: Agentic Attacks, Model

• UK Government Threatens Tech Bosses With Jail Time Over AI

• Here's How the FTC Plans to Enforce the Take It Down Act

View all
#Aviation5 articles

• Japan Airlines Confirms Data Breach Affecting 28,000

• Malaysia Airlines Listed by Qilin Ransomware Group

• Iranian APT Targets Aviation, Software Companies With

View all
#Gemini5 articles

• PromptSpy: First Android Malware to Weaponize Generative AI

• Critical Gemini CLI Flaw Enabled Host Code Execution

• Google Gemini CLI Jailbroken and Used as a Hacking Agent to Run a Malware Botnet

View all
#Hacktivism5 articles

• Pro-Russian Hacktivists Launch Sustained Cyber Campaign

• Operation Epic Fury Triggers Unprecedented Cyber Escalation

• Bearlyfy Hits Russian Firms with Custom GenieLocker

View all
#Telecommunications5 articles

• The World's First Transatlantic Fiber Cable Is Being Pulled

• Google Disrupts Massive Chinese Espionage Campaign

• FCC Proposes $4.5 Million Fine for Voice Provider Hosting

View all
#MongoDB5 articles

• IDMerit KYC Data Breach Exposes 1 Billion Records Across 26

• CVE-2026-19001: MongoDB BI Connector ODBC Driver Buffer Overflow (CVSS 9.8)

• CVE-2026-45688: Rocket.Chat CAS Login MongoDB Operator Injection (CVSS 9.1)

View all
#Cloudflare5 articles

• Cloudflare 2026 Threat Report: 230 Billion Daily Threats as

• Cloudflare BGP Routing Error Cascades Across AWS, X, and More

• CVE-2026-11325: Cloudflare pages-action GitHub Actions RCE

View all
#AiTM5 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

• Misconfigured Server Exposes Three Evilginx Phishing Ops Targeting M365

View all
#Extradition5 articles

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

• Ukrainian National Pleads Guilty to Role in Conti Ransomware Operation

• Alleged Scattered Spider Hacker Peter Stokes Extradited to the United States

View all
#Mandiant5 articles

• Cognizant TriZetto Breach Exposes Health Data of 3.4

• ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities

• Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack

View all
#Data Theft5 articles

• ShinyHunters Claims Mass Data Theft From 400 Firms via Salesforce Aura

• New BlackFile Extortion Group Linked to Surge of Vishing

• Colorado Governor Commutes Prison Sentence for Election

View all
#CRM5 articles

• ShinyHunters Claims Mass Data Theft From 400 Firms via Salesforce Aura

• Wesco Confirms Security Incident After ExfilSquad Claims 2.6M Record Theft

• Over 1,000 Charities Hit by Beacon CRM Data Breach

View all
#Bug5 articles

• Windows 11 February Update Breaks C:\ Drive Access on Samsung PCs

• Microsoft Teams Right-Click Paste Broken by Edge Update Bug

• Microsoft June 2026 Updates Break Recycle Bin Confirmation Prompts on All Windows Versions

View all
#SGLang5 articles

• AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable

• SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious

• CVE-2026-14890: SGLang ZeroMQ Unauthenticated RCE via Pickle Deserialization

View all
#Regulatory5 articles

• Microsoft Halts Forced Global Rollout of Microsoft 365

• FCC Proposes New Rule to Further Crack Down on Illegal

• GM to Pay Over $12 Million in Largest-Ever CCPA Fine Over

View all
#Financial Services5 articles

• Marquis Ransomware Breach: 672K People Exposed as Attack

• DORA and Operational Resilience: Credential Management as a

• American Lending Center Data Breach Affects 123,000

View all
#Kimwolf5 articles

• DoJ Disrupts 3 Million-Device IoT Botnets Behind Record

• Alleged Kimwolf Botmaster ''Dort'' Arrested, Charged in U.S. and Canada

• Canadian Man Arrested and Charged for Running KimWolf DDoS

View all
#Unauthorized Access5 articles

• Mazda Discloses Security Breach Exposing Employee and Partner Data

• CVE-2026-14950: 389 Directory Server Session Expiry Bypass Allows Unauthorized Access

• CVE-2026-25199: Apache CloudStack Proxmox Extension Allows

View all
#Initial Access Broker5 articles

• Russian Hacker Who Helped Yanluowang Ransomware Gang Gets

• FortiBleed: Russian IAB Harvested 110 Million Credentials from 430,000 FortiGate Firewalls

• FortiBleed: 5-Stage Attack Chain Behind 110 Million Credential Heist on FortiGate Firewalls

View all
#Nation State5 articles

• Iran-Linked Hackers Breach FBI Director's Personal Email

• Researchers Uncover Pre-Stuxnet 'fast16' Malware Targeting

• UK Cyberspying Chief Calls AI 'an Unstoppable Force' and Warns About Russia

View all
#Post-Quantum5 articles

• Google Slashes Quantum Resource Requirements for Breaking

• Kyber Ransomware Gang Uses Post-Quantum Encryption to Target Windows and ESXi

• Apple Open-Sources Quantum-Resistant Encryption Code

View all
#Wiper5 articles

• Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations

• Broken VECT 2.0 Ransomware Acts as a Data Wiper for Large

• Vect 2.0 Ransomware Acts as Wiper Thanks to Design Error

View all
#Chainguard5 articles

• The State of Trusted Open Source Report: Key Findings for 2025

• Chainguard Unveils Factory 2.0 to Automate Hardening the Software Supply Chain

• Growing Up The Hard Way: Open Source Security's Painful Maturation

View all
#SBOM5 articles

• The State of Trusted Open Source Report: Key Findings for 2025

• What Changes When AI Writes Your Code: Supply Chain Security in the Age of LLMs

• Growing Up The Hard Way: Open Source Security's Painful Maturation

View all
#Germany5 articles

• Die Linke German Political Party Confirms Data Stolen by Qilin Ransomware

• BKA Identifies REvil Leaders Behind 130 German Ransomware

• Police Shut Down Reboot of Crimenetwork Marketplace, Arrest

View all
#Credential Security5 articles

• Why Simple Breach Monitoring Is No Longer Enough

• Microsoft Backpedals: Edge to Stop Loading Cleartext

• MokN Raises $15 Million for Phish-Back Platform

View all
#IAM5 articles

• The Hidden Cost of Recurring Credential Incidents

• Gartner Identifies the Top 6 Cybersecurity Trends Reshaping

• CVE-2026-82856: @hulumi/policies GitHub OIDC Trust Policy Bypass

View all
#Apache ActiveMQ5 articles

• 13-Year-Old Bug in ActiveMQ Lets Hackers Remotely Execute

• ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache

• CISA Flags Apache ActiveMQ Flaw as Actively Exploited in Attacks

View all
#PDF5 articles

• Adobe Reader Zero-Day Exploited via Malicious PDFs Since

• Hackers Exploiting Acrobat Reader Zero-Day Flaw Since

• Adobe Patches Actively Exploited Zero-Day That Lingered for Months

View all
#EDR Bypass5 articles

• Payouts King Ransomware Uses QEMU Virtual Machines to Bypass Endpoint Security

• Making Vulnerable Drivers Exploitable Without Hardware: The

• GodDamn Ransomware Uses PoisonX Kernel Driver to Neutralize Endpoint Security

View all
#Virtualization5 articles

• Payouts King Ransomware Uses QEMU Virtual Machines to Bypass Endpoint Security

• NAKIVO v11.2: Ransomware Defense, Faster Replication

• CVE-2026-25199: Apache CloudStack Proxmox Extension Allows

View all
#Disaster Recovery5 articles

• NAKIVO v11.2: Ransomware Defense, Faster Replication

• Azure Backup: VMs, Files, and SQL with Recovery Services

• Implementing a Robust Backup Strategy: The 3-2-1 Rule

View all
#NIST5 articles

• NIST to Stop Rating Non-Priority Flaws Due to Volume

• Federal Audit Reveals NIST's NVD Is Plagued by Poor Planning and Duplication

• CISA Mandates Full Zero Trust Architecture for Federal

View all
#RMM5 articles

• Surge in Bomgar RMM Exploitation Demonstrates Supply Chain

• WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

• N-able Patches Max-Severity N-central RCE Amid Live Attacks

View all
#Checkmarx5 articles

• Malicious KICS Docker Images and VS Code Extensions Hit

• Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain

• Checkmarx Confirms GitHub Repository Data Posted on Dark

View all
#Password Manager5 articles

• Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain

• Dashlane Password Manager Users Locked Out by Brute Force Attacks

• Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

View all
#Mozilla5 articles

• Firefox Vulnerability Allows Tor User Fingerprinting Across

• CVE-2026-5731: Firefox and Thunderbird Critical Memory

• CVE-2026-6748: Critical Uninitialized Memory Flaw in Firefox and Thunderbird Web Codecs

View all
#Auth Bypass5 articles

• Hackers Exploit RCE Flaws in Qinglong Task Scheduler for Cryptomining

• Gitea Vulnerability Exposes Private Container Images without Authentication

• CVE-2026-18248: Fastify AWS Lambda Auth Bypass Allows Privilege Escalation

View all
#Go5 articles

• Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

• CVE-2026-15704: Critical Auth Bypass in Eclipse BaSyx Go Components

• CVE-2026-35392: Critical Path Traversal in goshs Go HTTP

View all
#AI Platform5 articles

• Fake OpenAI Repository on Hugging Face Pushes Infostealer

• Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

• CVE-2025-34291: Langflow Origin Validation Error

View all
#Malvertising5 articles

• Hackers Abuse Google Ads and Claude.ai Chats to Push Mac

• New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

• SourTrade: Malicious Sites Use JavaScript to Assemble Malware Directly in Browser Memory

View all
#Security Operations5 articles

• One Missed Threat Per Week: What 25M Alerts Reveal About

• Exaforce Raises $125 Million for Agentic SOC Platform

• Only 10% of SOCs Say They're Getting Excellent Value From AI — What the Second Wave Must Deliver

View all
#Security Update5 articles

• Microsoft May 2026 Patch Tuesday Fixes 120 Flaws, No

• FFmpeg Fixes PixelSmash Flaw in Widely Used Video Decoder

• Microsoft Fixes AutoGen Studio Flaw That Enabled Code Execution

View all
#Network-Security5 articles

• Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited

• Cisco Zero-Day Under Ongoing Attack by Persistent Threat

• Suricata IDS/IPS Deployment: From Install to Active Threat

View all
#Election Security5 articles

• Colorado Governor Commutes Prison Sentence for Election

• Can Laws Stop Deepfakes? South Korea Aims to Find Out

• ODNI Taps Officials to Coordinate Response to Foreign

View all
#PoC5 articles

• PoC Code Published for Critical NGINX Vulnerability

• MiniPlasma Windows 0-Day Enables SYSTEM Privilege

• Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

View all
#Rootkit5 articles

• ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI

• Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

• UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

View all
#Laravel5 articles

• Laravel Lang Packages Hijacked to Deploy

• Laravel-Lang PHP Packages Compromised to Deliver

• CVE-2025-54068: Laravel Livewire Code Injection

View all
#LiteSpeed5 articles

• LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run

• CISA Gives Feds 4 Days to Patch Actively Exploited cPanel Plugin Flaw

• CISA Urges Immediate Patching of Exploited LiteSpeed cPanel

View all
#OWASP5 articles

• Open Source DockSec Uses AI to Cut Through Vulnerability

• OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds

• Vague Task, Total Access: When AI Delegation Becomes a Security Risk

View all
#ICS Security5 articles

• Exposed Fuel Tank Gauges Under Attack in the US

• Russian Hackers Breached Polish Energy Plant via Private APN in World-First DER Cyberattack

• In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

View all
#Memory Safety5 articles

• Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities

• CVE-2026-5731: Firefox and Thunderbird Critical Memory

• CVE-2026-6748: Critical Uninitialized Memory Flaw in Firefox and Thunderbird Web Codecs

View all
#social-engineering5 articles

• WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

• Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

• Teen Suspect in Scattered Spider Hacks Is Extradited to US

View all
#AI Tools5 articles

• CISA Orders Feds to Prioritize Patching Langflow Auth Bypass Flaw

• 2-Click Cursor Exploit Enables Dev Environment Takeover

• Trojanized MCP Server Deploys StealC Infostealer Targeting

View all
#Outage5 articles

• OpenAI Confirms ChatGPT Is Down Worldwide — ~50-Minute Global Outage

• Microsoft Blames Massive Microsoft 365 Outage on Automated Maintenance Bug

• Cloudflare BGP Routing Error Cascades Across AWS, X, and More

View all
#Credential Exposure5 articles

• OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

• 768 Live AWS Keys with Full Admin Access Found Across Public Repos, AI Training Data, and Docker Images

• CVE-2025-36568: Dell PowerProtect Data Domain BoostFS

View all
#N-able5 articles

• CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

• China-Linked Storm-1175 Deploys StormEncryptor Ransomware via Critical N-central Flaw

• N-able Patches Max-Severity N-central RCE Amid Live Attacks

View all
#zero-trust5 articles

• When Credentials Are No Longer Enough: Device Trust in the AI Era

• HashiCorp Vault: Centralized Secrets Management for Modern

• OpenSSH Hardening with Certificate-Based Authentication

View all
#Wordfence5 articles

• Critical Avada WordPress Theme Flaw Enables Zero-Click RCE

• Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

• CVE-2026-12415: WordPress Invoice Generator Privilege Escalation (CVSS 9.8)

View all
#SSO5 articles

• Dropbox Accounts Breached Through Lenovo Email Verification Flaw

• CVE-2026-11374: ManageEngine SSO Ticket Prediction Enables Unauthenticated Account Takeover

• CVE-2026-15013: WordPress SAML SSO Plugin — Algorithm Confusion Auth Bypass

View all
#CWE-1215 articles

• CVE-2016-20049: JAD Java Decompiler Stack-Based Buffer

• CVE-2017-20225: TiEmu TI Calculator Emulator Stack Buffer

• CVE-2026-10187: Totolink N300RH Stack Buffer Overflow in WiFi Config

View all
#Ecommerce5 articles

• CVE-2020-37168: Systempay Weak Crypto Allows Payment

• CVE-2021-47923: OpenCart 3.0.3.8 Session Fixation Enables

• CVE-2025-65336: Critical SQL Injection in Fruits Bazar PHP Ecommerce

View all
#SOHO5 articles

• CVE-2024-51311: Critical Stack Overflow in Tenda TX9 Router Firmware

• CVE-2026-19977: EFM ipTIME A3004T Authentication Bypass — CVSS 10.0

• CVE-2026-31027: TOTOlink A3600R Buffer Overflow in setAppEasyWizardConfig

View all
#MLflow5 articles

• CVE-2025-15036: MLflow Path Traversal in Archive Extraction

• CVE-2025-15379: MLflow Command Injection in Model Serving

• CVE-2026-0596: MLflow Command Injection via Unsanitized

View all
#PowerProtect5 articles

• CVE-2025-36568: Dell PowerProtect Data Domain BoostFS

• CVE-2026-49814: Dell PowerProtect Data Domain OS Command Injection

• CVE-2026-53481: Dell PowerProtect Data Domain Path Traversal — CVSS 9.8

View all
#Remote Exploit5 articles

• CVE-2026-10263: SQL Injection in SourceCodester Computer Repair Shop Management System

• CVE-2026-14732: SQL Injection in SourceCodester Timetabling System via /edit_exam.php

• CVE-2026-14733: SQL Injection in SourceCodester Timetabling System via /edit_coursea.php

View all
#CVSS 9.65 articles

• CVE-2026-11807: Critical Authorization Bypass in Event-Driven Ansible WebSocket API

• CVE-2026-24303: Microsoft Partner Center Privilege

• CVE-2026-2611: MLflow 3.9.0 Improper Origin Validation

View all
#itsourcecode5 articles

• CVE-2026-14688: SQL Injection in itsourcecode Hotel Management Admin Login

• CVE-2026-3730: SQL Injection in itsourcecode Free Hotel

• CVE-2026-3740: SQL Injection in itsourcecode University

View all
#cve5 articles

• CVE-2026-15065: Reserved Vulnerability Advisory

• CVE-2026-58003: Reserved Security Advisory

• CVE-2026-59256: Reserved Security Advisory

View all
#CWE-5025 articles

• CVE-2026-25449: Critical Object Injection in Shinetheme

• CVE-2026-25769: Wazuh Critical RCE via Insecure

• CVE-2026-48207: Apache Fury PyFury Deserialization RCE

View all
#Template Injection5 articles

• CVE-2026-26026: GLPI Template Injection Enables

• CVE-2026-41258: OpenMRS Velocity Template Injection Enables

• CVE-2026-73043: SiYuan RCE via Template Calculation Operator

View all
#Identity Provider5 articles

• CVE-2026-29067: ZITADEL Password Reset Poisoned by Host Header Injection

• ZITADEL Critical XSS in SAML Endpoint Enables 1-Click

• CVE-2026-29192: ZITADEL Stored XSS via Default Redirect URI

View all
#PKI5 articles

• CVE-2026-30836: Step CA SCEP UpdateReq Allows

• CVE-2026-9648: X.509 NameConstraints Bypass in crypton-x509-validation

• HashiCorp Vault: Centralized Secrets Management for Modern

View all
#Network Device5 articles

• CVE-2026-31027: TOTOlink A3600R Buffer Overflow in setAppEasyWizardConfig

• CVE-2026-32956: Critical Heap Buffer Overflow in silex

• CVE-2026-7136: Totolink A8000RU OS Command Injection via setDmzCfg

View all
#Input Validation5 articles

• UniFi OS Command Injection via Improper Input Validation

• CVE-2026-47367: UID Enterprise Agent Command Injection via Improper Input Validation

• CVE-2026-47369: UniFi OS Privilege Escalation via Improper Input Validation

View all
#Knowledge Management5 articles

• CVE-2026-33669: SiYuan Unauthenticated Document Content

• CVE-2026-33670: SiYuan readDir Path Traversal Notebook

• CVE-2026-40259 — SiYuan Knowledge Management Authorization

View all
#Hard-Coded Credentials5 articles

• Dell ECS and ObjectScale: Hard-Coded Credentials

• CVE-2026-49191: M3WebServer Hard-Coded API Keys Exposed via Error Pages

• CVE-2026-50208: TLS Bypass and Hard-Coded DES Keys Enable MITM Attacks

View all
#Containers5 articles

• Container Security Scanning with Trivy: Images, IaC, and CI/CD

• Docker Security Hardening: Locking Down Container Environments

• Docker Security Fundamentals: Protecting Your Containers

View all
#threat-detection5 articles

• Suricata IDS/IPS Deployment: From Install to Active Threat

• Network Traffic Analysis with Zeek: From Deployment to Threat Detection

• Sysmon and Windows Event Forwarding: Enterprise-Grade

View all
#blue-team5 articles

• Network Traffic Analysis with Zeek: From Deployment to Threat Detection

• Sysmon and Windows Event Forwarding: Enterprise-Grade

• Deploy OpenCanary to Catch Attackers Inside Your Network

View all
#Banking4 articles

• FBI Warns of ATM Jackpotting Surge as Losses Top $20

• RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

• River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

View all
#Threat Actors4 articles

• Scattered Lapsus$ ShinyHunters Alliance Hits 100+

• Exposed Fuel Tank Gauges Under Attack in the US

• Klue OAuth Breach Linked to 'Icarus' Salesforce Data Theft Attacks

View all
#Fintech4 articles

• Fintech Giant Figure Technology Confirms Breach: Nearly 1

• Cash App Owner to Pay $45 Million Over Lax Security Allegations

• Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

View all
#Amazon4 articles

• AI-Armed Amateur Hacker Compromises 600+ FortiGate

• Amazon Fined $2.25M by FTC for Blocking Identity Theft Victims' Evidence

• 9,300+ Leaked AWS Keys Still Active, Granting Full Corporate Account Control

View all
#PhaaS4 articles

• Europol-Coordinated Action Dismantles Tycoon2FA — 330

• FBI Dismantles Massive AI-Powered Chinese Phishing-as-a-Service Operation

• Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

View all
#Guilty Plea4 articles

• Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

• Former DigitalMint Ransomware Negotiator Pleads Guilty to $75.3M Extortion Scheme

• Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

View all
#Spain4 articles

• Spanish-Ukrainian Police Bust Gambling Ring That Exploited

• Spain Dismantles Major $4.7M Manga Piracy Platform, Arrests

• Zara Data Breach Exposed Personal Information of 197,000

View all
#GlassWorm4 articles

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

• GlassWorm ForceMemo: Stolen GitHub Tokens Used to Poison

• Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach

View all
#Solana4 articles

• GlassWorm Escalates: 72 Malicious Open VSX Extensions Use

• Crypto Platform Drift Suspends Services After Hundreds of Millions Stolen

• Drift Crypto Platform Confirms $280 Million Stolen as

View all
#Hardware Security4 articles

• Eclypsium Raises $25 Million to Expand Device Supply Chain

• GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables

• New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

View all
#Trivy4 articles

• Trivy Security Scanner GitHub Actions Breached — 75 Tags

• Cisco Source Code Stolen in Trivy-Linked Dev Environment

• European Commission Confirms Data Breach Linked to Trivy

View all
#Streaming4 articles

• Crunchyroll Probes Breach After Hacker Claims to Steal 6.8M

• Anti-Piracy Coalition Takes Down AnimePlay App with 5

• Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming

View all
#NetScaler4 articles

• Citrix Urges Admins to Patch NetScaler Flaws as Soon as

• Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active

• Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks

View all
#CVE-2026-30554 articles

• Citrix Urges Admins to Patch NetScaler Flaws as Soon as

• Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active

• Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks

View all
#CVE-2025-535214 articles

• CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

• F5 BIG-IP Vulnerability Reclassified from DoS to RCE Under

• Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE

View all
#California4 articles

• Foster City Declares State of Emergency After Ransomware

• GM Agrees to $12.75M California Settlement Over Sale of Drivers' Data

• California AG Sues 23andMe Over 2023 Breach Exposing Genetic Health Data

View all
#European Commission4 articles

• European Commission Confirms Data Breach After Europa.eu

• CERT-EU: European Commission Hack Exposes Data of 30 EU

• EU Cyber Agency Attributes Major Data Breach to TeamPCP

View all
#TrueConf4 articles

• Hackers Exploit TrueConf Zero-Day to Push Malicious

• PhantomCore Exploits TrueConf Vulnerabilities to Breach

• Head Mare Hacktivists Breach TrueConf to Trojanize Client Installers with PhantomCore Backdoors

View all
#File Transfer4 articles

• New Progress ShareFile Flaws Can Be Chained in Pre-Auth RCE

• CISA: Hackers Now Exploit SolarWinds Serv-U Flaw to Crash Servers

• CVE-2026-14958: IBM Aspera Faspex 5 Shell Injection Enables RCE

View all
#Software Security4 articles

• The State of Trusted Open Source Report: Key Findings for 2025

• Build Application Firewalls Aim to Stop the Next Supply

• How Software Development's Speed Obsession Enabled TeamPCP's Chaos Crusade

View all
#Windows Update4 articles

• Microsoft Now Force-Upgrades Unmanaged Windows 11 24H2 PCs

• Windows Update Gets New Controls to Reduce Forced Restarts

• Microsoft Blames August 2026 Windows Gaming Crashes on RGB Lighting Devices

View all
#DPRK4 articles

• $285 Million Drift Hack Traced to Six-Month DPRK Social

• Drift $280M Crypto Theft Linked to 6-Month In-Person DPRK

• Amazon Links Debug, Chalk NPM Supply Chain Attacks to North Korean Hackers

View all
#Redis4 articles

• 36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

• Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

• Kimi K3 AI Agents Discovered Redis Zero-Days and Built RCE Exploits in Under 90 Minutes

View all
#PostgreSQL4 articles

• 36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

• Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites

• Critical RCE in Veeam Backup & Replication — Backup Viewer

View all
#Penetration Testing4 articles

• Black Hat USA 2026: What to Expect from the Year''s Biggest

• Nmap Scanning Techniques for Security Professionals

• OSINT Reconnaissance Methodology for Security Professionals

View all
#REvil4 articles

• Germany Doxes "UNKN," Head of RU Ransomware Gangs REvil

• BKA Identifies REvil Leaders Behind 130 German Ransomware

• German Authorities Identify REvil and GandCrab Ransomware

View all
#US Government4 articles

• Trump Budget Proposal Would Cut Hundreds of Millions More

• Commerce Setting Up New AI Export Regime to Push Adoption

• OpenAI Previews GPT-5.6 Sol Under Government-Gated Rollout with Stronger Cyber Safeguards

View all
#Unpatched4 articles

• Disgruntled Researcher Leaks BlueHammer Windows Zero-Day

• Windows BitLocker Zero-Day Gives Access to Protected

• Windows Zero-Days Expose BitLocker Bypasses and CTFMON

View all
#Storm-11754 articles

• Microsoft Links Storm-1175 to Medusa Ransomware Zero-Day

• China-Linked Storm-1175 Chains Zero-Days for High-Velocity

• Storm-1175 Deploys Medusa Ransomware at 'High Velocity'

View all
#Medusa4 articles

• China-Linked Storm-1175 Chains Zero-Days for High-Velocity

• Storm-1175 Deploys Medusa Ransomware at 'High Velocity'

• New StormEncryptor Ransomware Used by Former Medusa Affiliate

View all
#Snowflake4 articles

• Snowflake Customers Hit in Data Theft Attacks After SaaS

• Canadian Pleads Guilty to Snowflake Cloud Data-Theft Attacks

• Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

View all
#Banking Trojan4 articles

• Cybercriminals Target Accountants to Drain Russian Firms'

• SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

• Banking Trojans Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlight

View all
#Business Email Compromise4 articles

• Cybercriminals Target Accountants to Drain Russian Firms'

• ARToken PhaaS Exposes EvilTokens' Microsoft 365 Phishing Toolkit with AI-Powered BEC

• Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

View all
#Detection4 articles

• Your Next Breach Will Look Like Business as Usual

• How to Detect and Block ClickFix Attacks

• Runtime Security Monitoring with Falco: Detect Container

View all
#AppSec4 articles

• Analysis of 216M Security Findings Shows a 4x Increase in Critical Risk (2026 Report)

• Software Is Now Written at the Speed of Thought. Security Isn't.

• What Changes When AI Writes Your Code: Supply Chain Security in the Age of LLMs

View all
#Business Continuity4 articles

• The Backup Myth That Is Putting Businesses at Risk

• BridgePay Payment Gateway Knocked Offline by Ransomware

• What Rural Alberta Businesses Get Wrong About Ransomware

View all
#BeyondTrust4 articles

• Surge in Bomgar RMM Exploitation Demonstrates Supply Chain

• BeyondTrust Remote Support and PRA Critical RCE Under

• BeyondTrust Remote Support Pre-Authentication RCE Under

View all
#Piracy4 articles

• Spain Dismantles Major $4.7M Manga Piracy Platform, Arrests

• Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming

• Police Dismantles 9 Crime Groups in Illegal Streaming Crackdown

View all
#Hospitality4 articles

• New BlackFile Extortion Group Linked to Surge of Vishing

• ClickFix Campaign Targets European Hotels with Fake

• CVE-2026-14688: SQL Injection in itsourcecode Hotel Management Admin Login

View all
#Threat Actor4 articles

• New BlackFile Extortion Group Linked to Surge of Vishing

• TeamPCP Hackers Advertise Mistral AI Source Code Repos for Sale

• ShinyHunters Claims Brinks Home Breach, Threatens to Leak Stolen Data

View all
#JFrog4 articles

• Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain

• FFmpeg PixelSmash: CVE-2026-8461 Enables RCE via Crafted Video Files Across Thousands of Apps

• JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

View all
#Copilot4 articles

• Microsoft Now Lets Admins Uninstall Copilot on Enterprise

• SearchLeak: New Attack Turned Microsoft 365 Copilot into 1-Click Data Theft Tool

• Microsoft Announces Major Security Features for Copilot

View all
#Tor4 articles

• Firefox Vulnerability Allows Tor User Fingerprinting Across

• CryptoBandits Malware Doubles as a Backdoor, Abuses Tor for Stealthy C2

• Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

View all
#FTC4 articles

• FTC: Americans Lost Over $2.1 Billion to Social Media Scams

• Here's How the FTC Plans to Enforce the Take It Down Act

• FTC Warns of Record $3.5 Billion in Losses to Imposter Scams in 2025

View all
#Medtronic4 articles

• Medtronic Confirms Breach After Hackers Claim 9 Million

• Medtronic Hack Confirmed After ShinyHunters Threatens Data

• Medtronic Notifies Customers Impacted by ShinyHunters Data Breach

View all
#Robotics4 articles

• Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

• As Global Powers Explore Humanoid Robots, Cyber-Risk Looms

• Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE — One Starts Over Bluetooth

View all
#Canvas4 articles

• Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

• Canvas Breach Disrupts Schools & Colleges Nationwide

• Multiple Universities Forced to Reschedule Final Exams

View all
#OFAC4 articles

• In Other News: Scattered Spider Member Arrested, SOC

• The U.S. Sanctions Nobitex Crypto Exchange Used by Ransomware

• US Treasury Sanctions 1VPNS: The VPN Service Favored by Ransomware Groups

View all
#2FA4 articles

• Google Detects First AI-Generated Zero-Day Exploit in the Wild

• Hackers Used AI to Develop First Known Zero-Day 2FA Bypass

• Malicious Chrome Extension 'CL Suite' Steals Meta Business

View all
#Kerberos4 articles

• Why Changing Passwords Doesn't End an Active Directory

• CVE-2026-11861: FreeIPA AD Trust Bypass Lets Attackers Impersonate Kerberos Clients

• CVE-2026-13097: FreeIPA Privilege Escalation via Kerberos Principal Uniqueness Bypass

View all
#Corporate Security4 articles

• KongTuke Hackers Now Use Microsoft Teams for Corporate

• Kodak Admits Data Breach After ShinyHunters Hack Claims

• Accenture Confirms Data Breach After Hacker Claims Source Code Theft

View all
#Mini Shai-Hulud4 articles

• OpenAI Confirms Security Breach in TanStack Supply Chain

• TanStack Supply Chain Attack Hits Two OpenAI Employee

• TeamPCP Hackers Advertise Mistral AI Source Code Repos for Sale

View all
#Financial Security4 articles

• More Than $10 Million Stolen from Crypto Platform THORChain

• Why Chargebacks Are Just One Piece of the Fraud Puzzle

• SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

View all
#Shai-Hulud4 articles

• TeamPCP Ups the Game, Releases Shai-Hulud Worm's Source Code

• Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

• GitHub Confirms Being Hacked by TeamPCP, Says Customer Data

View all
#Defense4 articles

• The Boring Stuff Is Dangerous Now

• New U.S. Cyber Force Would Cost Up to $11 Billion to Start, Commission Says

• Cyber Force Not Included in Senate Defense Policy Roadmap

View all
#Acquisitions4 articles

• SecurityScorecard Acquires Driftnet to Boost Third-Party

• SailPoint to Acquire Entro in Reported $200 Million Deal

• Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions

View all
#Governance4 articles

• 5 Steps to Managing Shadow AI Tools Without Slowing Down

• Geordie Raises $30 Million for AI Security and Governance Platform

• Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

View all
#Drupal4 articles

• Drupal Patches Highly Critical Vulnerability Exposing

• Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites

• Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

View all
#Chromium4 articles

• Google Accidentally Exposed Details of Unfixed Chromium Flaw

• AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android

• CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

View all
#CMS Security4 articles

• Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites

• CVE-2026-39397: PayloadCMS Puck Plugin Access Control Bypass

• Critical Authentication Bypass in WordPress Temporary Login

View all
#Social Media4 articles

• Canadian Man Gets 33 Years for Using Social Media to Coerce US Children

• New Mexico Judge Orders Meta to Pay $567 Million in Kids Online Safety Case

• Senators Press TikTok Over Withholding Safety Features from Users

View all
#23andMe4 articles

• California AG Sues 23andMe Over 2023 Breach Exposing Genetic Health Data

• 23andMe $47 Million Settlement Approved for 7 Million Breach Victims

• 23andMe to Pay $18 Million in New Genetics Data Breach Settlement

View all
#GlobalProtect4 articles

• Palo Alto GlobalProtect VPN Auth Bypass Flaw Now Exploited in Attacks

• PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

• Critical Palo Alto VPN Bug Now Exploited by Qilin Ransomware Gang

View all
#VPN Security4 articles

• Palo Alto GlobalProtect VPN Auth Bypass Flaw Now Exploited in Attacks

• PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

• CISA Warns Fortinet Users to Secure Devices After FortiBleed Credential Leak

View all
#Dashlane4 articles

• Dashlane Password Manager Users Locked Out by Brute Force Attacks

• Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

• Dashlane Discloses Brute-Force Attack: Encrypted Vaults of Fewer Than 20 Users Downloaded

View all
#VoIP4 articles

• Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches

• Hackers Exploit Sangoma Switchvox Flaw to Deploy Reverse Shells

• CVE-2026-45538: OpenSIPS Stack Buffer Overflow via Oversized SIP Header

View all
#Pakistan4 articles

• Pakistan-Linked SideCopy APT Targets Afghanistan Finance Ministry with Xeno RAT

• China and India Ran Separate Spying Campaigns Against the Same Pakistani Police Force

• China and India-Linked Hackers Both Targeted the Same Pakistani Police Force

View all
#Cyber Policy4 articles

• New U.S. Cyber Force Would Cost Up to $11 Billion to Start, Commission Says

• Cyber Force Not Included in Senate Defense Policy Roadmap

• Launch of UK's National Cyber Action Plan Delayed Amid Labour Leadership Crisis

View all
#Rust4 articles

• IronWorm and New Miasma Worm Variant Hit npm in Coordinated Supply Chain Attacks

• Rust-Written IronWorm Hits NPM Supply Chain

• Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

View all
#FFmpeg4 articles

• AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

• FFmpeg Fixes PixelSmash Flaw in Widely Used Video Decoder

• FFmpeg PixelSmash: CVE-2026-8461 Enables RCE via Crafted Video Files Across Thousands of Apps

View all
#SolarWinds4 articles

• CISA: Hackers Now Exploit SolarWinds Serv-U Flaw to Crash Servers

• CVE-2026-28302: SolarWinds Serv-U IDOR Leads to Root RCE

• CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption (DoS)

View all
#PeopleSoft4 articles

• Oracle Mitigates PeopleSoft Zero-Day Exploited in Data Theft Attacks

• ShinyHunters Uses Oracle Zero-Day to Rampage Higher Education

• Google Confirms ShinyHunters Exploited Oracle PeopleSoft Zero-Day CVE-2026-35273

View all
#Enterprise Software4 articles

• Cyberattack on Russian Tech Firm Astral Disrupts Business and Government Services for a Week

• CVE-2022-4995: Weaver E-cology 9.0 Unauthenticated File Upload Enables Webshell RCE

• CVE-2025-62319: Critical SQL Injection in HCL Unica (CVSS

View all
#INC Ransomware4 articles

• INC Ransomware Thrives by Mastering the Basics

• Inc Ransomware Exploits Chained SonicWall SMA Zero-Days for Root Access

• INC Ransomware Emerges as Dominant Threat Actor Exploiting SonicWall SMA 1000 Flaws

View all
#JetBrains4 articles

• Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

• Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

• CVE-2026-59792: JetBrains IntelliJ IDEA Remote Code Execution via Path Traversal

View all
#Code Execution4 articles

• Microsoft Fixes AutoGen Studio Flaw That Enabled Code Execution

• CVE-2018-25320: ACL Analytics Arbitrary Code Execution via EXECUTE Function

• CVE-2026-32999: Comet Backup Server Code Execution via Signing Module

View all
#StealC4 articles

• Amadey and StealC Malware Networks Disrupted, 27 Million Stolen Credentials Recovered

• Microsoft and Europol Dismantle Three Cybercrime-as-a-Service Operations

• FakeGit Campaign Uses 7,600 GitHub Repos to Push SmartLoader Malware

View all
#Industry News4 articles

• In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs

• Nebulock Raises $25 Million for AI-Native Contextual Security

• Guten Tag, Bonjour, Hola: Dark Reading Launches European Cyber Defenders Hub

View all
#Threat Hunting4 articles

• Nebulock Raises $25 Million for AI-Native Contextual Security

• SentinelOne Threat Hunting Recipes: Practical Deep

• Velociraptor DFIR: Endpoint Forensics and Incident Response

View all
#ai-security4 articles

• Chinese LLMs Broaden the Gap Between Attackers & Defenders

• Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

• Venture Firm Team8 Secures Additional $365 Million

View all
#Third Party Risk4 articles

• Lidl Discloses Online Shop Breach After Service Provider Hack

• Origin Energy Data Breach Affects 900,000 Australians

• Pokemon Center Data Breach Exposes Customer Info, Cancels Some Orders

View all
#Data Security4 articles

• Cyera Acquiring Oasis Security in $1 Billion Deal

• Varonis Launches Agent IBAC to Keep AI Agents Within Their Intended Boundaries

• Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

View all
#Remote Access4 articles

• Microsoft Teams Vishing Attacks Lead to Chaos Ransomware Deployment

• CVE-2026-3564: ConnectWise ScreenConnect Auth Bypass via Server Cryptographic Material

• FortiGate SSL VPN Setup: Secure Remote Access Configuration

View all
#Payment Security4 articles

• Interpol Leverages Global System to Curtail Fraud Payments

• CVE-2020-37168: Systempay Weak Crypto Allows Payment

• CVE-2026-11964: WordPress User Registration Plugin PayPal Webhook Bypass

View all
#data-breach4 articles

• Hackers Steal 31,000 Records Identifying People Behind Liechtenstein Companies and Foundations

• Valve Notifies Steam Hardware Customers of CEVA Logistics Data Breach

• CareCloud Data Breach Exposes 3.75 Million Patient Records

View all
#Apache Tomcat4 articles

• CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

• CVE-2016-20026: ZKTeco ZKBioSecurity 3.0 Hardcoded Tomcat

• CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

View all
#ransomware4 articles

• N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

• China-Linked Storm-1175 Turns N-able N-central Into MSP Ransomware Launchpad

• Enterprise Perimeter Defenses Improved — Interior Security Collapsed

View all
#vulnerability4 articles

• Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miner

• CISA Warns of Hackers Exploiting Critical MLflow Vulnerability

• Critical Elementor Pro Bug Exposes WordPress Sites to RCE Attacks

View all
#critical4 articles

• CISA Warns of Hackers Exploiting Critical MLflow Vulnerability

• Critical Elementor Pro Bug Exposes WordPress Sites to RCE Attacks

• Critical Keycloak Flaw Lets Attackers Reset Any Account Password Without Authentication

View all
#NASA4 articles

• NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

• DoJ Corrects China Hacking Claim: Agencies Were Targets, Not Victims

• CVE-2024-46636: NASA EOSDIS MODAPS v8.1 SQL Injection

View all
#United Kingdom4 articles

• Manchester Airports Group Confirms Data Breach — Up to 8.9M Travelers Affected

• 68-Year-Old Imprisoned After Making $1.3 Million by Pirating IPTV Services

• FulcrumSec Claims Manchester Airports Hack, Theft of 86GB of Data

View all
#Patchstack4 articles

• Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

• Critical GiveWP Flaw Lets Hackers Run Server Commands

• CVE-2026-32479: Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro

View all
#SCADA4 articles

• Cyberattacks on Critical Infrastructure Double in Q1 2026

• CVE-2026-12183: Critical Auth Bypass in Gas Station Automation System

• CVE-2026-16462: PROCON-WEB SCADA Unauthenticated SQL Injection (CVSS 9.8)

View all
#Coolify4 articles

• Coolify CVE-2026-34037: CVSS 9.9 IDOR Enables Cross-Team Resource Takeover

• Coolify CVE-2026-34047: Terminal WebSocket Authorization Bypass (CVSS 9.9)

• Coolify CVE-2026-34048: Low-Privilege Terminal Escalation via WebSocket (CVSS 9.9)

View all
#CSRF4 articles

• CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability

• CVE-2026-2611: MLflow 3.9.0 Improper Origin Validation

• CVE-2026-3589: WooCommerce CSRF Flaw Allows Unauthenticated

View all
#CPAN4 articles

• CVE-2011-10043: Perl Module::Load Arbitrary Module Injection Resurfaces

• CVE-2025-15618: Perl Payment Module Uses Insecure

• CVE-2026-8507: Crypt::OpenSSL::PKCS12 Heap OOB Write — CVSS

View all
#Stack Overflow4 articles

• CVE-2016-20049: JAD Java Decompiler Stack-Based Buffer

• CVE-2017-20225: TiEmu TI Calculator Emulator Stack Buffer

• CVE-2017-20230: Perl Storable Stack Overflow — CVSS 10.0

View all
#CWE-4344 articles

• CVE-2016-20052: Snews CMS 1.7 Unrestricted File Upload

• CVE-2021-47933: WordPress MStore API 2.0.6 Arbitrary File

• CVE-2021-47936: OpenCATS 0.9.4 Unauthenticated RCE via PHP

View all
#AJAX4 articles

• CVE-2021-47932: WordPress TheCartPress 1.5.3.6 Privilege

• CVE-2026-12923: YouTube Showcase WordPress Plugin Arbitrary Function Call

• CVE-2026-13423: Streamit WordPress Theme Allows Unauthenticated Arbitrary PHP Function Execution

View all
#CWE-2694 articles

• CVE-2021-47932: WordPress TheCartPress 1.5.3.6 Privilege

• CVE-2026-25770: Wazuh Privilege Escalation to Root via Cluster Protocol File Write

• CVE-2026-32922: OpenClaw Privilege Escalation via Token

View all
#Object Injection4 articles

• WordPress ARForms Plugin Critical PHP Object Injection — CVE-2024-13784

• CVE-2026-0551: PHP Object Injection in PPWP – Password Protect Pages WordPress Plugin

• CVE-2026-25449: Critical Object Injection in Shinetheme

View all
#CVSS 9.94 articles

• CVE-2025-14771: ABB T-MAC Plus Critical File & Directory Exposure (CVSS 9.9)

• CVE-2026-14450: MaaS API Auth Bypass via Forged HTTP Headers

• CVE-2026-18948: Feast Feature Store RCE via Unsafe Deserialization

View all
#Education Software4 articles

• CVE-2025-67403: Critical SQL Injection in CASAP Enrollment System update_class.php

• CVE-2025-67404: Critical SQL Injection in CASAP Enrollment System save_stud.php

• CVE-2026-11334: SQL Injection in College Management System

View all
#Unauthenticated Access4 articles

• CVE-2026-11841: AppEngine Fileaccess Unauthenticated Filesystem R/W (CVSS 9.4)

• CVE-2026-28766: Gardyn Smart Garden API Exposes All User

• CVE-2026-34162: FastGPT Unauthenticated HTTP Proxy Enables

View all
#LDAP4 articles

• CVE-2026-11861: FreeIPA AD Trust Bypass Lets Attackers Impersonate Kerberos Clients

• CVE-2026-13097: FreeIPA Privilege Escalation via Kerberos Principal Uniqueness Bypass

• CVE-2026-18922: SASL Auth Flaw Lets Attackers Seize Directory Manager on 389 Directory Server

View all
#Embedded Device4 articles

• CVE-2026-12485: GeoVision GV-I/O Box 4E UDP Stack Overflow (IP Address Field)

• CVE-2026-12486: GeoVision GV-I/O Box 4E OS Command Injection via libNetSetObj.so

• CVE-2026-12846: GeoVision GV-I/O Box 4E UDP Stack Overflow (Net Mask Field)

View all
#SSTI4 articles

• CVE-2026-14453: Critical SSTI to RCE in Centreon Open Tickets (CVSS 9.6)

• GlassFish Gadget Handler Expression Language RCE

• CVE-2026-44377: CubeCart Authenticated SSTI via Smarty

View all
#CWE-3474 articles

• CVE-2026-15013: WordPress SAML SSO Plugin — Algorithm Confusion Auth Bypass

• CVE-2026-31946: Critical JWT Signature Verification Bypass

• CVE-2026-3564: ConnectWise ScreenConnect Auth Bypass via Server Cryptographic Material

View all
#CWE-6394 articles

• CVE-2026-2346: Critical Authorization Bypass in Menulux Mobile App

• Critical Session Hijacking via Auth Bypass in Akilli

• CVE-2026-25197: IDOR Flaw Lets Authenticated Users Access

View all
#Image Processing4 articles

• CVE-2026-40492: SAIL XWD Codec Heap Buffer Overflow (CVSS

• CVE-2026-40493: SAIL PSD Codec Buffer Overflow via channels

• CVE-2026-40494: SAIL TGA Codec RLE Decoder Asymmetric

View all
#Avi Load Balancer4 articles

• CVE-2026-47865: Critical Authentication Bypass in VMware Avi Load Balancer

• CVE-2026-47866: Authorization Bypass in VMware Avi Load Balancer

• CVE-2026-47867: Remote Code Execution via Code Injection in VMware Avi Load Balancer

View all
#APSB26-684 articles

• CVE-2026-48276: Adobe ColdFusion Critical File Upload RCE (CVSS 10.0)

• CVE-2026-48277: Adobe ColdFusion Critical Input Validation RCE (CVSS 10.0)

• CVE-2026-48281: Adobe ColdFusion Input Validation RCE Zero-Day (CVSS 10.0)

View all
#Incus4 articles

• CVE-2026-48749: Incus Malicious Image Arbitrary File Write and RCE (CVSS 9.9)

• CVE-2026-48750: Incus Exec-Output Symlink Attack Enables Host File Write (CVSS 9.9)

• CVE-2026-62940: Incus Migration Security Restriction Bypass (CVSS 9.9)

View all
#OT4 articles

• OpENer CIP Integer Overflow — CVE-2026-51536

• OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537

• OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538

View all
#File Write4 articles

• CVE-2026-56260: Crawl4AI Arbitrary File Write in Docker API

• CVE-2026-56445: DICOM qrscp Path Traversal Enables Arbitrary File Write

• CVE-2026-57898: Eclipse BaSyx Unauthenticated File Write in IIoT SDK (CVSS 9.0)

View all
#Thunderbird4 articles

• CVE-2026-5731: Firefox and Thunderbird Critical Memory

• CVE-2026-6748: Critical Uninitialized Memory Flaw in Firefox and Thunderbird Web Codecs

• CVE-2026-6785: Memory Safety Bugs in Firefox and Thunderbird Enable Arbitrary Code Execution

View all
#Network Devices4 articles

• CVE-2026-71948: D-Link DWR-M961 Command Injection via formDebugDiagnosticRun

• CVE-2026-71949: D-Link DWR-M961 Command Injection via formUSSDSetup

• CVE-2026-71950: D-Link DWR-M961 Command Injection via formSmsManage

View all
#MSI4 articles

• MSI Radix AXE6600 Critical Command Injection in WPS Interface (CVE-2026-71983)

• MSI Radix AXE6600 Critical Command Injection in URL Filter Function (CVE-2026-71984)

• MSI Radix AXE6600 Critical Command Injection in Access Control Function (CVE-2026-71985)

View all
#OIDC4 articles

• CVE-2026-73683: Laravel Socialite Facebook OIDC Authentication Bypass

• CVE-2026-82856: @hulumi/policies GitHub OIDC Trust Policy Bypass

• How to Secure GitHub Actions Workflows with OIDC, SHA

View all
#DFIR4 articles

• Velociraptor DFIR Setup, Hunts, and Forensic Collection

• Osquery Endpoint Visibility & Threat Hunting

• Incident Response Playbook: Ransomware

View all
#Conditional Access4 articles

• The Microsoft 365 Security Baseline Every Small Business Should Have

• Conditional Access Policies: Zero Trust with Entra ID

• Microsoft 365 Security and Compliance Configuration Guide

View all
#linux4 articles

• WireGuard VPN: Secure Remote Access for IT Professionals

• AIDE File Integrity Monitoring: Detect Unauthorized Changes on Linux

• OpenSSH Hardening with Certificate-Based Authentication

View all
#XDR4 articles

• How to Deploy Wazuh SIEM/XDR for Unified Security Monitoring

• Microsoft Defender for Endpoint: Configuration and Hardening

• Building a Wazuh XDR + SIEM Homelab

View all
#Intune4 articles

• Microsoft Defender for Endpoint: Configuration and Hardening

• Intune Device Enrollment: Windows Autopilot Setup

• Microsoft 365 Security Baseline Implementation

View all
#device-control4 articles

• SentinelOne Control vs Complete Feature Comparison

• SentinelOne Device Control: Block USB & Bluetooth Devices

• SentinelOne MSP Client Onboarding

View all
#Verizon3 articles

• Senator Demands AT&T, Verizon CEOs Testify Over Salt

• Verizon DBIR 2026: Healthcare Fends Off Rising Social

• What the 2026 DBIR Confirms: Attacks Are Living in the Browser

View all
#Antitrust3 articles

• Google's $32 Billion Wiz Acquisition Clears Final Hurdle as

• Google Loses Final Appeal to Overturn €4.1 Billion EU Antitrust Fine

• EU Fines Google $1 Billion for Search and App Store DMA Violations

View all
#DHS3 articles

• IRS Shares Tax Data of 1.28 Million Individuals with DHS

• CISA Loses 62% of Workforce as DHS Shutdown Guts America's

• DHS Confirms Hackers Breached HSIN Federal Info-Sharing Platform

View all
#Trends3 articles

• Ransomware in 2026: Data-Only Extortion Replaces Encryption

• Cybersecurity Predictions 2026: The Hype We Can Ignore and the Real Risks

• Ransomware Attacks Surge 49% Year-Over-Year: BlackFog 2026

View all
#Lapsus$3 articles

• Scattered Lapsus$ ShinyHunters Alliance Hits 100+

• Mercor Confirms Security Incident Tied to LiteLLM Supply

• Blast Radius of TeamPCP Attacks Expands Amid Hacker

View all
#Biometrics3 articles

• Persona Source Code Leak Exposes Hidden Biometric

• UK to Require Government ID or Face Scan Before Creating Social Media Accounts

• The Future of Age Verification: Your Face Never Leaves Your Device

View all
#Age Verification3 articles

• Persona Source Code Leak Exposes Hidden Biometric

• UK to Require Government ID or Face Scan Before Creating Social Media Accounts

• The Future of Age Verification: Your Face Never Leaves Your Device

View all
#Italy3 articles

• Pro-Russian Hacktivists Launch Sustained Cyber Campaign

• Italian Regulator Fines National Postal Service Orgs $15

• Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming

View all
#Semiconductor3 articles

• Japanese Semiconductor Giant Advantest Hit by Ransomware

• Analog Devices Discloses Data Breach, Says Operations Unaffected

• Semiconductor Chip Titan Analog Devices Reports Data Breach

View all
#Logistics3 articles

• Diesel Vortex: Russian Cybercrime Ring Steals 1,649

• FBI Links Cybercriminals to Sharp Surge in Cargo Theft

• OnTrac Notifies Customers of Data Breach After Network Hack

View all
#Israel3 articles

• Iran Plunged Into Digital Darkness: Internet Drops to 4% in Cyberattack

• Operation Epic Fury Triggers Unprecedented Cyber Escalation

• Researchers Detect ZionSiphon Malware Targeting Israeli

View all
#ALPHV3 articles

• Former Cybersecurity Responders Plead Guilty to BlackCat Attacks

• US Ransomware Negotiators Get 4 Years in Prison Over

• Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

View all
#Defense Strategy3 articles

• The Zero-Day Scramble Is Avoidable: Why Attack Surface

• 73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation

• The Race to Field Military Autonomy Is On — Can Trusted Information Infrastructure Keep Pace?

View all
#Cybercrime Takedown3 articles

• Operation Synergia III: Police Sinkhole 45,000 IPs in Global Cybercrime Crackdown

• Police Shut Down Reboot of Crimenetwork Marketplace, Arrest

• FBI and Google Dismantle 'Outsider Enterprise' Phishing-as-a-Service Platform

View all
#MDM3 articles

• Stryker Cyberattack Wiped Tens of Thousands of Devices — No

• Microsoft Now Lets Admins Uninstall Copilot on Enterprise

• CVE-2026-49185: FieldX MDM ADB Topic Command Injection via Runtime.exec()

View all
#CVE-2026-24413 articles

• Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach

• Google Patches First Chrome Zero-Day of 2026: CVE-2026-2441

• Google Chrome Use-After-Free Zero-Day Under Active

View all
#Akira3 articles

• Marquis Ransomware Breach: 672K People Exposed as Attack

• Akira Hackers Disable EDR with Safe Mode, Steal Data but Fail to Encrypt

• Ransomware Attacks Surge in Early 2026 with 26 Claims in One Day

View all
#AI Infrastructure3 articles

• Eclypsium Raises $25 Million to Expand Device Supply Chain

• Adani Pledges $100 Billion for Renewable-Powered AI Data

• CVE-2026-24207: NVIDIA Triton Inference Server Auth Bypass

View all
#DarkSword3 articles

• DarkSword GitHub Leak Threatens to Turn Elite iPhone

• TA446 Deploys DarkSword iOS Exploit Kit in Targeted

• Apple Expands iOS 18 Updates to More iPhones to Block

View all
#Web Skimmer3 articles

• PolyShell Attacks Target 56% of All Vulnerable Magento

• WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

• Polymarket Customers Lose $3 Million in Supply-Chain Attack

View all
#Hacktivist3 articles

• Pro-Ukraine Hacker Group Bearlyfy Targets Russian Companies

• PhantomCore Exploits TrueConf Vulnerabilities to Breach

• Head Mare Hacktivists Breach TrueConf to Trojanize Client Installers with PhantomCore Backdoors

View all
#Steganography3 articles

• Backdoored Telnyx PyPI Package Pushes Malware Hidden in WAV

• TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides

• APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine

View all
#Spear-Phishing3 articles

• TA446 Deploys DarkSword iOS Exploit Kit in Targeted

• APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine

• Fake Microsoft Security Alerts Used to Deploy North Korean NarwhalRAT Malware

View all
#NCII3 articles

• Dutch Court Threatens xAI with Fines Over Grok's

• UK Government Threatens Tech Bosses With Jail Time Over AI

• NY Man Charged After Harassing College Student with AI-Generated Nude Images

View all
#FCC3 articles

• FCC Bans Import of Foreign-Made Consumer Routers Over

• FCC Proposes $4.5 Million Fine for Voice Provider Hosting

• FCC Proposes New Rule to Further Crack Down on Illegal

View all
#CISO3 articles

• The State of Secrets Sprawl 2026: 9 Takeaways for CISOs

• Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

• CISOs Break Their Silence in 'Declassified' Docuseries

View all
#AI Security Research3 articles

• Claude AI Finds Vim and Emacs RCE Bugs That Trigger on File

• AI-Assisted HTTP Terminator Finds Novel Desync Techniques and Apache Zero-Day

• Critical Avada WordPress Theme Flaw Enables Zero-Click RCE

View all
#UNC10693 articles

• Axios NPM Package Breached in North Korean Supply Chain

• Google Attributes Axios npm Supply Chain Attack to North

• North Korean Hackers Use Fake Zoom Meeting to Target Crypto

View all
#Hack3 articles

• Crypto Platform Drift Suspends Services After Hundreds of Millions Stolen

• $3 Million Reportedly Stolen in Polymarket Hack

• Truebit Protocol Hit by $26.5 Million DeFi Hack via Smart

View all
#Crypto Heist3 articles

• Drift Crypto Platform Confirms $280 Million Stolen as

• Drift Loses $280 Million as Hackers Seize Security Council

• KelpDAO Suffers $290 Million Heist Tied to Lazarus Hackers

View all
#Drift Protocol3 articles

• Drift Crypto Platform Confirms $280 Million Stolen as

• Drift Loses $280 Million as Hackers Seize Security Council

• 'It Reads Like a Spy Novel': $280M Drift Theft Linked to North Korean Fake Companies

View all
#Governance Attack3 articles

• Drift Crypto Platform Confirms $280 Million Stolen as

• Drift Loses $280 Million as Hackers Seize Security Council

• Attackers Vote Themselves $20 Million in BONK Cryptocurrency via Governance Attack

View all
#Shadowserver3 articles

• Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE

• Actively Exploited Apache ActiveMQ Flaw Impacts 6,400

• GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

View all
#Texas3 articles

• 250,000 Affected by Data Breach at Nacogdoches Memorial

• Texas Govt Data Breach Exposes Over 3 Million Driver's Licenses

• Texas Parks & Wildlife Data Breach Affects 3 Million Individuals

View all
#Zendesk3 articles

• Hims & Hers Warns of Data Breach After Zendesk Support

• 300,000+ Passport Numbers Leaked in December Eurail Data

• Hims & Hers Breach Exposes the Most Sensitive Kinds of Patient PHI

View all
#Black Hat3 articles

• Black Hat USA 2026: What to Expect from the Year''s Biggest

• AI-Assisted HTTP Terminator Finds Novel Desync Techniques and Apache Zero-Day

• New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

View all
#GandCrab3 articles

• Germany Doxes "UNKN," Head of RU Ransomware Gangs REvil

• BKA Identifies REvil Leaders Behind 130 German Ransomware

• German Authorities Identify REvil and GandCrab Ransomware

View all
#DNS Hijacking3 articles

• Authorities Disrupt APT28 Router DNS Hijacks Targeting

• Russia's Forest Blizzard Harvests Logins via SOHO Router

• CubePilot Drone Software Dev Hit by DNS Hijacking to Intercept Traffic

View all
#IC33 articles

• FBI: Americans Lost a Record $21 Billion to Cybercrime Last

• FBI: Cybercrime Losses Neared $21 Billion in 2025

• FBI: Americans Lost Over $388 Million to Crypto ATM Scams

View all
#Investment Fraud3 articles

• FBI: Americans Lost a Record $21 Billion to Cybercrime Last

• FBI: Cybercrime Losses Neared $21 Billion in 2025

• US Charges Two New Yorkers for Laundering $43 Million in Pig Butchering Investment Fraud

View all
#Ninja Forms3 articles

• Hackers Exploit Critical Flaw in Ninja Forms WordPress

• CVE-2026-65048: Ninja Forms Unauthenticated Stored XSS via Repeatable Fieldset

• CVE-2026-65049: Ninja Forms Multisite Flaw Enables Network-Wide Data Deletion

View all
#cyber insurance3 articles

• The Hidden Cost of Recurring Credential Incidents

• Why Every Business Needs Cyber Insurance in 2026

• The 10 Controls Every Canadian Cyber-Insurance Carrier Asks About in 2026

View all
#Passport Data3 articles

• 300,000+ Passport Numbers Leaked in December Eurail Data

• Eurail Says December Data Breach Impacts 300,000 Individuals

• 220 Million Traveler Records Exposed in Vietnam-Linked APIS Leak

View all
#Acrobat Reader3 articles

• Adobe Reader Zero-Day Exploited via Malicious PDFs Since

• Hackers Exploiting Acrobat Reader Zero-Day Flaw Since

• CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution

View all
#Online Safety Act3 articles

• UK Government Threatens Tech Bosses With Jail Time Over AI

• UK to Require Government ID or Face Scan Before Creating Social Media Accounts

• UK Brings AI Chatbots Under the Online Safety Act

View all
#Productivity3 articles

• Microsoft Teams Right-Click Paste Broken by Edge Update Bug

• Microsoft Teams to Get Efficiency Mode for Low-Resource PCs

• Microsoft Rolls Out Classic Outlook Theme for New Outlook Users

View all
#Mirai3 articles

• Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack

• New Mirai Campaign Exploits RCE Flaw in End-of-Life D-Link

• New Evooo1Bot Linux Botnet Turns Routers Into Traffic Relay Nodes

View all
#Water Security3 articles

• Researchers Detect ZionSiphon Malware Targeting Israeli

• Iran, Russia, and China Target Water Systems for Sabotage

• Senate Democrats Introduce Water Cyber Shield Act to Fund $300M Annual Water System Cybersecurity

View all
#Performance3 articles

• Microsoft Teams to Get Efficiency Mode for Low-Resource PCs

• Claude Fable Relaunch Disappoints Users With Nerfed Performance

• FortiGate Performance Optimization: A Tuning Guide for Throughput

View all
#CVE-2026-38443 articles

• Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

• Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

• CVE-2026-3844 — Breeze Cache WordPress Plugin

View all
#ADT3 articles

• ADT Confirms Data Breach After ShinyHunters Leak Threat

• ADT Says Customer Data Stolen in Cyber Intrusion

• Home Security Giant ADT Data Breach Affects 5.5 Million

View all
#Bitwarden3 articles

• Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain

• ETH Zurich Finds 25 Password Recovery Attacks Against

• Self-Hosted Password Manager with Vaultwarden

View all
#Exchange Server3 articles

• Microsoft Patch Tuesday, March 2026 Edition

• Microsoft Patches Exploited Exchange Server Vulnerability CVE-2026-42897

• Microsoft Exchange Server SSRF to RCE Chain Actively

View all
#Consumer Security3 articles

• FTC: Americans Lost Over $2.1 Billion to Social Media Scams

• Chick-fil-A Discloses Data Breach After Credential Stuffing Attacks

• Chick-fil-A Data Breach Affects More Than 13,000 Customers

View all
#Have I Been Pwned3 articles

• Home Security Giant ADT Data Breach Affects 5.5 Million

• Zara Data Breach Exposed Personal Information of 197,000

• Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

View all
#Zero-Click3 articles

• Incomplete Windows Patch Opens Door to Zero-Click Attacks

• Apple Sends New Threat Notification Alerts Over Mercenary Spyware Attacks

• Mail2Shell: Zero-Click RCE in FreeScout Helpdesk

View all
#Medical Devices3 articles

• Medtronic Confirms Breach After Hackers Claim 9 Million

• Medtronic Hack Confirmed After ShinyHunters Threatens Data

• Medical Device Maker Notifies Nearly 4 Million Patients of Data Breach

View all
#Crypto Fraud3 articles

• Money Launderer Linked to $230M Crypto Heist Gets 70 Months

• European Police Dismantles €50 Million Crypto Investment

• US & China Partner on Scam Center Takedown in Dubai

View all
#ConnectWise3 articles

• CISA Adds Actively Exploited ConnectWise and Windows Flaws

• CVE-2024-1708: ConnectWise ScreenConnect Path Traversal

• CVE-2026-3564: ConnectWise ScreenConnect Auth Bypass via Server Cryptographic Material

View all
#OpenEMR3 articles

• AI Finds 38 Security Flaws in Electronic Health Record

• CVE-2026-32238: Critical Command Injection in OpenEMR

• CVE-2026-39932: Critical RCE in OpenEMR via PHP Payload Injection

View all
#Instructure3 articles

• Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

• Multiple Universities Forced to Reschedule Final Exams

• Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65 TB Canvas Leak

View all
#Trellix3 articles

• Trellix Confirms Source Code Breach With Unauthorized

• Trellix Source Code Breach Claimed by RansomHouse Hackers

• Trellix Source Code Breach Highlights Growing Supply Chain

View all
#RansomHouse3 articles

• Trellix Source Code Breach Claimed by RansomHouse Hackers

• Trellix Source Code Breach Highlights Growing Supply Chain

• RansomHouse Freezes Japan's Food Supply: Nichirei Logistics Cyberattack Disrupts KFC and Thousands of Clients

View all
#WHM3 articles

• cPanel & WHM Release Fixes for Three New Vulnerabilities

• CVE-2026-41940: WebPros cPanel & WHM and WP2 Missing

• CVE-2026-47365: WordPress Toolkit Argument Injection in cPanel & WHM

View all
#CCPA3 articles

• GM to Pay Over $12 Million in Largest-Ever CCPA Fine Over

• GM to Pay Over $12 Million in California Privacy Settlement

• GM Agrees to $12.75M California Settlement Over Sale of Drivers' Data

View all
#Higher Education3 articles

• Multiple Universities Forced to Reschedule Final Exams

• ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities

• ShinyHunters Uses Oracle Zero-Day to Rampage Higher Education

View all
#CI/CD Security3 articles

• Build Application Firewalls Aim to Stop the Next Supply

• Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

• CVE-2026-44246: nnU-Net Agentic Workflow Injection via GitHub Actions Issue Triage

View all
#Windows Security3 articles

• Why Changing Passwords Doesn't End an Active Directory

• Configuring Windows LAPS: Automated Local Admin Password

• Group Policy Security Hardening for Windows Environments

View all
#Venture Capital3 articles

• Exaforce Raises $125 Million for Agentic SOC Platform

• Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation

• AegisAI Raises $36 Million for AI-Powered Email Security

View all
#FortiSandbox3 articles

• Fortinet Warns of Critical RCE Flaws in FortiSandbox and FortiAuthenticator

• Attackers Hit Pair of Critical Fortinet Vulnerabilities the Vendor Disclosed in April

• CISA Orders Immediate Patching of Actively Exploited Fortinet FortiSandbox Flaws

View all
#Pharmaceutical3 articles

• West Pharmaceutical Services Hit by Disruptive Ransomware

• West Pharmaceutical Warns of Ransomware Attack Impacting

• Pharma Giant Novo Nordisk Discloses Breach of Clinical Trials Data

View all
#Foxconn3 articles

• Foxconn Confirms Cyberattack Claimed by Nitrogen Ransomware

• Foxconn Confirms North American Factories Hit by Cyberattack

• Foxconn Attack Highlights Manufacturing's Cyber Crisis

View all
#Poland3 articles

• ''FrostyNeighbor'' APT Carefully Targets Govt Orgs in Poland, Ukraine

• Russian Hackers Breached Polish Energy Plant via Private APN in World-First DER Cyberattack

• Poland Probes MyDr Healthcare Software Breach Potentially Affecting 19 Million

View all
#Exchange3 articles

• Microsoft Warns of Exchange Zero-Day Flaw Exploited in Attacks

• Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

• Microsoft Exchange Zero-Day Under Attack, No Patch Available

View all
#Source Code Theft3 articles

• TeamPCP Hackers Advertise Mistral AI Source Code Repos for Sale

• Grafana Says Stolen GitHub Token Let Hackers Steal Codebase

• Accenture Confirms Data Breach After Hacker Claims Source Code Theft

View all
#Responsible Disclosure3 articles

• Microsoft Rejects Critical Azure Vulnerability Report, No

• Microsoft Says Zero-Day Public Releases Are 'Never Justifiable' as Researcher Threatens More Drops

• Microsoft's Zero-Day Legal Threats Spark Backlash

View all
#7-Eleven3 articles

• 7-Eleven Data Breach Confirmed After ShinyHunters Ransom

• 7-Eleven Confirms Data Breach Claimed by the ShinyHunters

• 185,000 Likely Impacted by 7-Eleven Data Breach

View all
#Bug Bounty3 articles

• Hackers Earn $1,298,250 for 47 Zero-Days at Pwn2Own Berlin

• Bug Bounty Research Triggers ServiceNow Security Alert

• In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

View all
#Scam3 articles

• FBI: Americans Lost Over $388 Million to Crypto ATM Scams

• Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

• Indian Man Who Fled US Arrested for Helping Scammers Siphon $7.5M from the Elderly

View all
#Industry Analysis3 articles

• Looking Back, Looking Forward: Two Decades of Cybersecurity

• Cybersecurity Evolution: From Perimeter Defense to AI-Native Security

• Ransomware Costs Projected to Hit $74 Billion in 2026, 30%

View all
#App Store3 articles

• Apple Blocked Over $11 Billion in App Store Fraud in 6 Years

• Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention

• Apple Sued Over Fake App Store Crypto Wallet That Stole $1.8M in Bitcoin

View all
#Bulletproof Hosting3 articles

• Netherlands Seizes 800 Servers of Hosting Firm Enabling

• Dutch Raid Fails to Dent Russian Bulletproof Host THE.Hosting

• US Charges Three Russians for Operating Bulletproof Hosting Behind $62M Ransomware Campaign

View all
#BYOVD3 articles

• Making Vulnerable Drivers Exploitable Without Hardware: The

• 'GodDamn' Ransomware Uses BYOVD Technique to Kill Security Software at US Companies

• Reynolds Ransomware Embeds BYOVD Driver to Disable EDR

View all
#Consumer Privacy3 articles

• Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People

• Charter Communications Data Breach Affects 4.9 Million Accounts

• Man Sent to Prison for Selling Data of 7 Million Elderly Americans

View all
#Gogs3 articles

• Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

• New Gogs Zero-Day Flaw Lets Hackers Get Remote Code Execution

• ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit

View all
#Disclosure3 articles

• Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

• OpenAI Admits It Didn't Disclose Rogue AI Wiki Hijacking Incident

• CVE-2026-58053: Newly Disclosed Informational Vulnerability

View all
#AI Abuse3 articles

• ChatGPT Share Links Abused to Host Fake Outage Pages Delivering Malware

• NY Man Charged After Harassing College Student with AI-Generated Nude Images

• Aurora Ransomware Operators Use Cursor AI Against 10 Targets

View all
#Frontier AI3 articles

• Frontier AI Reinforces the Future of Modern Cyber Defense

• OpenAI Previews GPT-5.6 Sol Under Government-Gated Rollout with Stronger Cyber Safeguards

• OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

View all
#Domain Controller3 articles

• Critical Windows Netlogon RCE Flaw Now Exploited in Attacks

• Domain Controller Hardening: Securing Active Directory

• Active Directory Health Check: Comprehensive Diagnostic

View all
#Residential Proxy3 articles

• Dutch Police Dismantle Massive 17-Million-Device Botnet

• Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices

• NetNut Proxy Network Disrupted, 2 Million Infected Devices Cut Off

View all
#EDR Evasion3 articles

• AI-Built Ransomware Toolkit Automates EDR Evasion and AD Discovery

• The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

• Reynolds Ransomware Embeds BYOVD Driver to Disable EDR

View all
#Account Security3 articles

• Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

• One Line of Code Put Billions of Microsoft Android App Downloads at Risk

• Infostealers Are Hijacking Stolen Claude Sessions to Drain Usage

View all
#Risk Assessment3 articles

• Security of 100 AI Agents Tested and Ranked – What You Need to Know

• Ransomware Costs Projected to Hit $74 Billion in 2026, 30%

• Vulnerability Management Checklist

View all
#Smart TV3 articles

• Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI

• NetNut Proxy Network Disrupted, 2 Million Infected Devices Cut Off

• LG to Ban Residential Proxies from Smart TV Apps

View all
#Vulnerability Scanning3 articles

• OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds

• Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund

• Build a Vulnerability Scanning Lab with OpenVAS

View all
#Serv-U3 articles

• CISA: Hackers Now Exploit SolarWinds Serv-U Flaw to Crash Servers

• CVE-2026-28302: SolarWinds Serv-U IDOR Leads to Root RCE

• CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption (DoS)

View all
#ServiceNow3 articles

• Bug Bounty Research Triggers ServiceNow Security Alert

• "City-Forum" Data-Theft Attacks Target Salesforce and ServiceNow Portals

• One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

View all
#The Gentlemen3 articles

• Who Runs the Ransomware Group 'The Gentlemen'?

• The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

• Ransomware Gang Claims Nutex Health Data Breach

View all
#SocGholish3 articles

• 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

• Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

• Microsoft and Europol Dismantle Three Cybercrime-as-a-Service Operations

View all
#Industrial Security3 articles

• Accenture to Acquire Majority Stake in Dragos, runZero, and NetRise in $4.1 Billion OT Cybersecurity Push

• Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

• CVE-2026-8153: Universal Robots PolyScope OS Command

View all
#AI Governance3 articles

• French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation

• Microsoft, Tech Companies Throw Weight Behind Spread of Open-Source AI

• India Hosts Global AI Impact Summit — 20 World Leaders and Tech CEOs

View all
#Wallet Security3 articles

• USB Worm Spreads Crypto-Stealing Malware via Windows Shortcut Files

• Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

• CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

View all
#FortiBleed3 articles

• FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist

• Russian Initial Access Broker Behind FortiBleed Campaign

• FortiBleed Credential-Theft Campaign Linked to Lynx Ransomware Group

View all
#Pig Butchering3 articles

• Chinese DCloud Uni-App Framework Powers 200,000+ Global Investment Scam Sites

• US Charges Two New Yorkers for Laundering $43 Million in Pig Butchering Investment Fraud

• SE Asian Cybercriminal Syndicates Become a Global Power

View all
#Browser Extension3 articles

• Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

• Google and Microsoft Pull ModHeader After Hidden Tracker Found in 1.6M-Install Extension

• Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

View all
#Insurance3 articles

• NAIC Says Only Public Data Stolen in ShinyHunters PeopleSoft Breach

• Insurance Giant Aflac Discloses Data Breach After Subsidiary Hack

• CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

View all
#Cursor IDE3 articles

• Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

• 2-Click Cursor Exploit Enables Dev Environment Takeover

• CVE-2026-63093: Cursor for Windows Binary Planting Allows RCE via Malicious Git Repository

View all
#India3 articles

• China and India Ran Separate Spying Campaigns Against the Same Pakistani Police Force

• Adani Pledges $100 Billion for Renewable-Powered AI Data

• India Hosts Global AI Impact Summit — 20 World Leaders and Tech CEOs

View all
#Reconnaissance3 articles

• Ghost Accounts Abuse GitHub API in Mass Recon Campaign

• Nmap Scanning Techniques for Security Professionals

• OSINT Reconnaissance Methodology for Security Professionals

View all
#CVE-2026-154093 articles

• SonicWall Warns of SMA1000 Flaws Exploited in Zero-Day Attacks, Patch Now

• SonicWall Warns of Two Zero-Day Exploits Targeting SMA1000 — Patch Immediately

• Prolific Ransomware Group Behind SonicWall Zero-Day Attacks

View all
#CVE-2026-154103 articles

• SonicWall Warns of SMA1000 Flaws Exploited in Zero-Day Attacks, Patch Now

• SonicWall Warns of Two Zero-Day Exploits Targeting SMA1000 — Patch Immediately

• Prolific Ransomware Group Behind SonicWall Zero-Day Attacks

View all
#Cursor3 articles

• Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

• Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

• Aurora Ransomware Operators Use Cursor AI Against 10 Targets

View all
#OpenSSL3 articles

• HollowByte: 11-Byte Payload Triggers Memory Bloat DoS on OpenSSL Servers

• HollowByte: 11-Byte Payload Triggers OpenSSL Server Memory Exhaustion

• CVE-2026-8507: Crypt::OpenSSL::PKCS12 Heap OOB Write — CVSS

View all
#Africa3 articles

• Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits

• Angola's Largest Telco Breached Hours Before IPO

• Police Arrest 58 Suspects in Global Cybercrime Crackdown

View all
#Machine Learning Security3 articles

• JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware

• CVE-2025-15379: MLflow Command Injection in Model Serving

• CVE-2026-0596: MLflow Command Injection via Unsanitized

View all
#Arista3 articles

• Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks

• CVE-2024-27890: Arista EOS OpenConfig gNMI Authorization Bypass (CVSS 9.6)

• CVE-2024-27892: Arista EOS OpenConfig gNMI Set Bypass (CVSS 9.6)

View all
#Autonomous Attacks3 articles

• Chinese Threat Actor Uses DeepSeek and Hermes Agent to Launch Fully Autonomous Cyberattacks

• Hacker Uses DeepSeek AI to Autonomously Attack Vulnerable Servers

• Chinese Hacker Uses DeepSeek via Telegram to Launch Fully Autonomous Cyberattacks

View all
#malware3 articles

• Hotel Wi-Fi Attacks Use Custom Malware to Breach Microsoft 365 Accounts

• 737 Chrome VPN Extensions Caught Routing Traffic Through Attacker Proxies

• WordlistLoader and SynkLoader: Two New Windows Malware Loaders Analysed

View all
#Webmail3 articles

• New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

• Hackers Breach Govt Webmail While Running Parallel Crypto Fraud

• CISA Adds Two Actively Exploited Roundcube Webmail Flaws to KEV

View all
#Business Intelligence3 articles

• Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

• Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

• Critical RCE in Hitachi Vantara Pentaho via Unrestricted

View all
#phishing3 articles

• When Credentials Are No Longer Enough: Device Trust in the AI Era

• Valve Notifies Steam Hardware Customers of CEVA Logistics Data Breach

• FBI: Hackers Using Social Engineering to Breach Accounts and Steal Explicit Content

View all
#MITM3 articles

• Signal Adds Automatic Key Verification to Thwart Man-in-the-Middle Attacks

• CVE-2026-48144: Apache Thrift c_glib TLS Certificate Host Mismatch (CVSS 9.1)

• Apache HttpComponents TLS Hostname Verification Bypass

View all
#open-source3 articles

• Who Vets AI's Code? The Scale Challenge Facing Open Source Ingestion

• Building a SOAR Platform with Shuffle in Your Homelab

• OWASP DefectDojo: Self-Hosted Vulnerability Management Platform

View all
#Trezor3 articles

• 14,000 Trezor Customers Impacted by Data Breach at ShipMonk

• Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

• Trezor Data Breach Impact Now Reaches 81,000 Customers

View all
#Industrial3 articles

• Philips and GE Investigating Clop Ransomware Data Theft Claims

• CVE-2017-20237: Hirschmann HiVision Auth Bypass Enables

• CVE-2025-67038: Lantronix EDS5000 OS Command Injection Vulnerability

View all
#aws3 articles

• CareCloud Data Breach Exposes 3.75 Million Patient Records

• Healthtech Firm CareCloud Data Breach Impacts 3.7 Million Patients

• CVE-2026-64849: MLflow SSRF Webhook Bypass Actively Exploited

View all
#rce3 articles

• Critical Elementor Pro Bug Exposes WordPress Sites to RCE Attacks

• CVE-2026-50540: Kata Containers Host Code Execution via Unvalidated Config Path

• CVE-2026-77946: TRENDnet TEW-821DAP Critical Stack Buffer Overflow

View all
#TikTok3 articles

• Senators Press TikTok Over Withholding Safety Features from Users

• TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

• TikTok Reaches $400M Settlement with DOJ Over COPPA Children's Privacy Violations

View all
#COPPA3 articles

• TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

• TikTok Reaches $400M Settlement with DOJ Over COPPA Children's Privacy Violations

• Meta Agrees to $18 Billion Settlement Over Teen Social Media Harms

View all
#ATF3 articles

• ATF Confirms 'Major Incident' After Qilin Ransomware Gang Claims Breach

• ATF Confirms Breach of System Holding Investigation Targets, Qilin Claims Credit

• ATF Breach Hit System Holding Investigation-Target Data, Officials Say

View all
#DevOps Security3 articles

• Over 8,300 Gitea Servers Still Vulnerable to Active Code Execution Attacks

• CVE-2026-20896: Gitea Docker Image Authentication Bypass

• CVE-2026-22874: Gitea SSRF Filter Bypass Exposes Cloud Credentials

View all
#PaperCut3 articles

• PaperCut Releases Second Emergency Patch for Exploited Flaws

• Recently Patched PaperCut Zero-Days Used in Data Theft Attacks

• CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability

View all
#CVE-2026-815783 articles

• PaperCut Releases Second Emergency Patch for Exploited Flaws

• Recently Patched PaperCut Zero-Days Used in Data Theft Attacks

• CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability

View all
#CVE-2026-820783 articles

• PaperCut Releases Second Emergency Patch for Exploited Flaws

• Recently Patched PaperCut Zero-Days Used in Data Theft Attacks

• CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability

View all
#PrestaShop3 articles

• 5,400+ Hacked Sites Serve ClickFix Payloads Stored on the Blockchain

• CVE-2026-39079: PrestaShop UPS Shipping Module Sensitive

• CVE-2026-44212: PrestaShop Stored XSS in Customer Service

View all
#Elementor3 articles

• Elementor Pro Flaw Exploited to Hack WordPress Sites, 190K+ Attempts Blocked

• CVE-2026-10081: Unlimited Elements for Elementor Stored XSS via Google Reviews

• Critical Unauthenticated RCE in JetEngine WordPress Plugin (CVE-2026-66613)

View all
#Statistics3 articles

• 2026 Vulnerability Forecast: Up to 117,000 CVEs Expected

• Ransomware Costs Projected to Hit $74 Billion in 2026, 30%

• Ransomware Attacks Surge 49% Year-Over-Year: BlackFog 2026

View all
#M3653 articles

• Microsoft Hit by Back-to-Back Outages: M365 Admin Center

• Microsoft Announces Major Security Features for Copilot

• The Microsoft 365 Security Baseline Every Small Business Should Have

View all
#Notepad++3 articles

• Notepad++ Supply Chain Attack Attributed to China-Linked

• CVE-2026-52884: Notepad++ Trusted Directory Bypass via Path Traversal (CVSS 7.8)

• Lotus Blossom APT Compromises Notepad++ Updates to Deploy

View all
#Google TAG3 articles

• Russian-Linked CANFAIL Malware Targets Ukrainian Defense

• Apple Patches Actively Exploited iOS Zero-Day Used in Targeted Attacks

• Apple Patches Actively Exploited Zero-Day in dyld

View all
#End of Life3 articles

• Samsung Ends Software Support for Galaxy S21 Series

• CISA Adds Ajax.NET Professional Deserialization RCE to KEV Catalog

• CVE-2026-85222: D-Link DNS-340L Command Injection Has No Fix Coming

View all
#CVE-2026-17313 articles

• BeyondTrust Remote Support and PRA Critical RCE Under

• BeyondTrust Remote Support Pre-Authentication RCE Under

• BeyondTrust Zero-Day Allows Unauthenticated Command

View all
#ZKTeco3 articles

• CVE-2016-20024: ZKTeco ZKTime.Net Insecure File Permissions

• CVE-2016-20026: ZKTeco ZKBioSecurity 3.0 Hardcoded Tomcat

• CVE-2016-20030: ZKTeco ZKBioSecurity 3.0 Username

View all
#CORS3 articles

• CVE-2025-34291: Langflow Origin Validation Error

• Critical CORS + Path Traversal in TinaCMS CLI Dev Server

• CVE-2026-61736: LightRAG Critical CORS Credential Bypass (CVSS 9.3)

View all
#Session Management3 articles

• CVE-2025-36359: IBM DevOps Session Hijacking Vulnerability (CVSS 8.1)

• CVE-2026-13332: Masteriyo LMS Allows Unauthenticated Force-Logout of Any User

• CVE-2026-14950: 389 Directory Server Session Expiry Bypass Allows Unauthorized Access

View all
#Data Domain3 articles

• CVE-2025-36568: Dell PowerProtect Data Domain BoostFS

• CVE-2026-53481: Dell PowerProtect Data Domain Path Traversal — CVSS 9.8

• CVE-2026-53483: Dell PowerProtect Data Domain Authentication Bypass — CVSS 9.8

View all
#Apache Airflow3 articles

• CVE-2025-57735: Apache Airflow JWT Token Not Invalidated on Logout

• CVE-2026-33264: Apache Airflow Scheduler RCE via DAG Deserialization

• CVE-2026-58065: Apache Airflow Git Provider Disables SSH Host Key Verification

View all
#Remote Exploitation3 articles

• CVE-2026-10184: SourceCodester Hospital Records SQL Injection via Delete

• CVE-2026-10185: SourceCodester Hospital Records SQL Injection via Save

• CVE-2026-10236: Improper Authorization in SourceCodester Water Billing Management System

View all
#WebSphere3 articles

• CVE-2026-11707: IBM WebSphere Application Server Admin Console XSS (CVSS 9.3)

• CVE-2026-14446: IBM WebSphere Admin Console Privilege Escalation

• CVE-2026-14512: IBM WebSphere Pre-Auth Deserialization Allows RCE

View all
#Remote Management3 articles

• CVE-2026-11849: IRM-IEI Remote Management Hardcoded Credentials

• Hard-Coded SSH Credentials Expose Lightstar SmartIT Desktop Manager

• Hard-Coded Fixed Password in SmartIT Desktop Manager Enables Host Takeover

View all
#Improper Authentication3 articles

• CVE-2026-14205: WP Events Manager Plugin Allows Fraudulent Paid Event Bookings via Payment Bypass

• CVE-2026-53471: migration-planner JWT Source ID Claim Not Validated in Agent API

• KodExplorer fileGet Auth Bypass — Unauthenticated Remote

View all
#Missing Authentication3 articles

• CVE-2026-14622: Missing Authentication in Restaurant Website PHP/MySQL AJAX Endpoint

• CVE-2026-4312: DrangSoft GCB/FCB Audit Software Missing

• CVE-2026-6577: DjangoBlog Missing Authentication in OwnTracks logtracks Endpoint

View all
#CodeIgniter3 articles

• CVE-2026-14635: Unrestricted File Upload RCE in CodeIgniter Ecommerce Bootstrap

• CVE-2026-14637: PHP Deserialization RCE in CodeIgniter Ecommerce Bootstrap Shopping Cart

• CVE-2026-48062: CodeIgniter File Upload Validation Bypass (CVSS 9.8)

View all
#MySQL3 articles

• CVE-2026-14641: Remote SQL Injection in SourceCodester Class and Exam Timetabling System

• CVE-2026-14642: Remote SQL Injection in SourceCodester Timetabling System edit_class2.php

• CVE-2026-48188: OTRS Database Layer SQL Injection — Authentication Bypass

View all
#Admin Panel3 articles

• CVE-2026-14653: SQL Injection in Shopping Cart Men's Product Delete Endpoint

• CVE-2026-14654: SQL Injection in Shopping Cart Girls Product Delete Endpoint

• CVE-2026-9525: SQL Injection in itsourcecode Electronic

View all
#reserved3 articles

• CVE-2026-15065: Reserved Vulnerability Advisory

• CVE-2026-58003: Reserved Security Advisory

• CVE-2026-59256: Reserved Security Advisory

View all
#Server-Side Request Forgery3 articles

• CVE-2026-19516: SSRF in mcp-grafana Allows Arbitrary Outbound Requests

• scalar/astro Proxy Endpoint Unauthenticated SSRF

• Typecho 1.3.0 Pingback SSRF via X-Pingback Manipulation

View all
#LibRaw3 articles

• CVE-2026-20889: LibRaw x3f_thumb_loader Heap Buffer

• CVE-2026-20911: LibRaw HuffTable::initval Heap Buffer

• CVE-2026-21413: LibRaw lossless_jpeg_load_raw Heap Buffer

View all
#RAW Image3 articles

• CVE-2026-20889: LibRaw x3f_thumb_loader Heap Buffer

• CVE-2026-20911: LibRaw HuffTable::initval Heap Buffer

• CVE-2026-21413: LibRaw lossless_jpeg_load_raw Heap Buffer

View all
#Reverse Proxy3 articles

• CVE-2026-20896: Gitea Docker Image Authentication Bypass

• CVE-2026-35051: Traefik ForwardAuth Authentication Bypass

• Multi-Stack Docker Infrastructure with Traefik and Authentik

View all
#Domain User3 articles

• Veeam Backup & Replication Auth RCE — CVE-2026-21666

• Veeam Backup & Replication 2nd Auth RCE — CVE-2026-21667

• Critical RCE in Veeam Backup & Replication — Third Domain

View all
#CWE-2843 articles

• CVE-2026-21994: Critical Unauthenticated RCE in Oracle Edge

• CVE-2026-25199: Apache CloudStack Proxmox Extension Allows

• CVE-2026-34162: FastGPT Unauthenticated HTTP Proxy Enables

View all
#Spring Security3 articles

• CVE-2026-22753: Spring Security Filter Chain Bypass via PathPattern Matcher

• CVE-2026-34263 — SAP Commerce Cloud Unauthenticated RCE

• CVE-2026-59354: Spring Security OAuth2 Authorization Server Dynamic Client Registration Flaw

View all
#Spinnaker3 articles

• CVE-2026-25534: Spinnaker SSRF via URL Validation Bypass

• CVE-2026-32604: Spinnaker Clouddriver Remote Code Execution

• CVE-2026-32613: Spinnaker Echo Spring Expression Language

View all
#CWE-223 articles

• CVE-2026-25770: Wazuh Privilege Escalation to Root via Cluster Protocol File Write

• CVE-2026-33670: SiYuan readDir Path Traversal Notebook

• CVE-2026-7302: SGLang Unauthenticated Path Traversal

View all
#Out-of-Bounds3 articles

• CVE-2026-28815: swift-crypto X-Wing HPKE Out-of-Bounds Read

• CVE-2026-4149: Sonos Era 300 Unauthenticated RCE via SMB

• OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537

View all
#ZITADEL3 articles

• CVE-2026-29067: ZITADEL Password Reset Poisoned by Host Header Injection

• ZITADEL Critical XSS in SAML Endpoint Enables 1-Click

• CVE-2026-29192: ZITADEL Stored XSS via Default Redirect URI

View all
#Unbound3 articles

• CVE-2026-33278 — NLnet Labs Unbound DNSSEC Validator RCE

• CVE-2026-42960 — NLnet Labs Unbound DNS Cache Poisoning

• Pi-hole v6 + Unbound: Network-Wide DNS Sinkhole with Recursive Resolution

View all
#LXD3 articles

• CVE-2026-34177: Canonical LXD Incomplete VM Restriction

• CVE-2026-34178: Canonical LXD Backup Import Path

• CVE-2026-66897: Critical LXD Path Traversal Allows Host File Overwrite

View all
#Canonical3 articles

• CVE-2026-34177: Canonical LXD Incomplete VM Restriction

• CVE-2026-34178: Canonical LXD Backup Import Path

• CVE-2026-5412: Juju Controller Facade Allows Low-Privilege

View all
#Prototype Pollution3 articles

• CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution

• vm2 Prototype Chain Escape via Function.prototype.call Stacking (CVE-2026-47698)

• CVE-2026-78207: Critical Prototype Pollution in exceljs-hardened Before v5.0.0

View all
#MiTM3 articles

• CVE-2026-35560: Amazon Athena ODBC Driver Fails Certificate

• CVE-2026-50208: TLS Bypass and Hard-Coded DES Keys Enable MITM Attacks

• CVE-2026-58065: Apache Airflow Git Provider Disables SSH Host Key Verification

View all
#Header Injection3 articles

• CVE-2026-39858: Traefik Forwarded-Header Sanitization

• CVE-2026-40453: Apache Camel Header Filter Case-Variant

• CVE-2026-71485: Critical Header Injection in Centrifugo Real-Time Messaging Server

View all
#Apache Camel3 articles

• CVE-2026-40047: Apache Camel Docling Argument Injection Enables OS Command Execution

• CVE-2026-40453: Apache Camel Header Filter Case-Variant

• CVE-2026-40860: Apache Camel JMS Unsafe ObjectMessage

View all
#SAIL3 articles

• CVE-2026-40492: SAIL XWD Codec Heap Buffer Overflow (CVSS

• CVE-2026-40493: SAIL PSD Codec Buffer Overflow via channels

• CVE-2026-40494: SAIL TGA Codec RLE Decoder Asymmetric

View all
#CWE-7983 articles

• Dell ECS and ObjectScale: Hard-Coded Credentials

• Hard-Coded SSH Credentials Expose Lightstar SmartIT Desktop Manager

• Hard-Coded Fixed Password in SmartIT Desktop Manager Enables Host Takeover

View all
#Server Administration3 articles

• CVE-2026-41228 — Froxlor Path Traversal via def_language

• CVE-2026-41229 — Froxlor PHP Code Injection via MySQL

• SSH Hardening Best Practices

View all
#Apache MINA3 articles

• CVE-2026-41635: Apache MINA Class Allowlist Bypass Enables

• Apache MINA Incomplete Deserialization Patch Leaves 2.1.X

• CVE-2026-42779: Critical Apache MINA Deserialization Class

View all
#authentik3 articles

• CVE-2026-42849: authentik Critical XSS in AutosubmitStage (CVSS 9.3)

• CVE-2026-49448: authentik Source Stage Authentication Bypass (CVSS 9.8)

• Multi-Stack Docker Infrastructure with Traefik and Authentik

View all
#CWE-3063 articles

• CVE-2026-4312: DrangSoft GCB/FCB Audit Software Missing

• CVE-2026-61514: Puwell IP Camera Authentication Bypass

• CVE-2026-6577: DjangoBlog Missing Authentication in OwnTracks logtracks Endpoint

View all
#GitOps3 articles

• CVE-2026-43824: Argo CD ServerSideDiff Exposes Cleartext

• Kubernetes Secrets Management with External Secrets Operator

• Kubernetes Homelab Cluster with K3s

View all
#Injection3 articles

• CVE-2026-45688: Rocket.Chat CAS Login MongoDB Operator Injection (CVSS 9.1)

• CVE-2026-45689: Rocket.Chat OAuth Token Hijack via MongoDB Operator Injection (CVSS 9.1)

• CVE-2026-56699: Critical NDJSON Injection in Wazuh Manager (CVSS 10.0)

View all
#OpENer3 articles

• OpENer CIP Integer Overflow — CVE-2026-51536

• OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537

• OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538

View all
#EtherNet/IP3 articles

• OpENer CIP Integer Overflow — CVE-2026-51536

• OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537

• OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538

View all
#CIP3 articles

• OpENer CIP Integer Overflow — CVE-2026-51536

• OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537

• OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538

View all
#migration-planner3 articles

• CVE-2026-53469: migration-planner Missing Authorization on Bulk Delete

• CVE-2026-53470: migration-planner IDOR Exposes Cross-Tenant S3 Pre-Signed URLs

• CVE-2026-53471: migration-planner JWT Source ID Claim Not Validated in Agent API

View all
#Backup Security3 articles

• CVE-2026-53481: Dell PowerProtect Data Domain Path Traversal — CVSS 9.8

• CVE-2026-53483: Dell PowerProtect Data Domain Authentication Bypass — CVSS 9.8

• CVE-2026-73600: Dell PowerProtect Data Manager Stack Buffer Overflow

View all
#Termix3 articles

• CVE-2026-53545: Termix SSH Tunnel Command Injection — CVSS 9.8 Critical

• CVE-2026-53546: Termix WebSocket Host Bypass Grants Cross-User SSH Access

• CVE-2026-53548: Termix IDOR Exposes All Stored SSH Passwords to Any User

View all
#Broken Access Control3 articles

• CVE-2026-53546: Termix WebSocket Host Bypass Grants Cross-User SSH Access

• CVE-2026-53548: Termix IDOR Exposes All Stored SSH Passwords to Any User

• CVE-2026-65007: Grav API Plugin Broken Authorization Allows API Key Takeover

View all
#HTML Injection3 articles

• CVE-2026-55674: Discourse Unauthenticated HTML Injection via Cookie

• CVE-2026-8043: Ivanti Xtraction File Control & HTML

• CVE-2026-8445: justhtml Markdown Conversion XSS via Unescaped Angle Brackets

View all
#OAuth23 articles

• CVE-2026-59354: Spring Security OAuth2 Authorization Server Dynamic Client Registration Flaw

• Apache CXF OAuth2 Scope Injection Lets Clients Claim Admin Privileges

• CVE-2026-9733: Mojolicious OAuth2 Weak PRNG Enables CSRF Session Hijacking

View all
#ERP3 articles

• CVE-2026-59500: Priority Portal Generator Authentication Bypass — CVSS 10.0

• CVE-2026-59504: Priority Portal Generator Client-Side Security Bypass (CVSS 9.1)

• Business Central Docker Containers: Development Environment

View all
#End of Life Software3 articles

• CVE-2026-6885: Borg SPM 2007 Arbitrary File Upload Enables

• CVE-2026-6886: Borg SPM 2007 Authentication Bypass Allows

• CVE-2026-6887: Borg SPM 2007 SQL Injection Exposes Full

View all
#Grav CMS3 articles

• CVE-2026-72819: Grav CMS RCE via ZIP Upload Bypass in Flex Objects Plugin

• CVE-2026-72822: Grav API Plugin 2FA Scope Bypass Allows Admin Account Takeover

• CVE-2026-72824: Grav API Plugin Twig Toggle Bypass Escalates Least-Privilege Keys

View all
#OSINT3 articles

• CVE-2026-75626: SpiderFoot Stored XSS via Unsanitized Correlation Titles

• OSINT Reconnaissance Methodology for Security Professionals

• Build a Dedicated OSINT Investigation Workstation

View all
#hulumi3 articles

• CVE-2026-82855: @hulumi/policies Cross-Resource Evidence Validation Bypass

• CVE-2026-82856: @hulumi/policies GitHub OIDC Trust Policy Bypass

• CVE-2026-82857: hulumi Privilege Escalation via Weekly Integration IAM Policy

View all
#FortiOS3 articles

• Fortinet FortiOS SSL VPN Heap Overflow Enables Pre-Auth RCE

• FortiGate Performance Optimization: A Tuning Guide for Throughput

• FortiGate Security Hardening: Best Practices for Enterprise

View all
#Router Vulnerability3 articles

• CVE-2026-86152: Max-Severity Tenda CP3 Command Injection via AutoAddWifi

• CVE-2026-86151: Tenda CP3 OS Command Injection via Network Config Handler

• CVE-2026-86153: Tenda CP3 Improper Privilege Management in Redirect Service

View all
#vulnerability-scanning3 articles

• Container Security Scanning with Trivy: Images, IaC, and CI/CD

• OpenVAS / Greenbone: Open-Source Vulnerability Scanning

• Nuclei Vulnerability Scanning Pipeline

View all
#IDS3 articles

• Suricata IDS/IPS Deployment: From Install to Active Threat

• Network Monitoring Basics: Detect Threats Before They Spread

• Network Traffic Analysis with Zeek and Suricata

View all
#intrusion-detection3 articles

• Suricata IDS/IPS Deployment: From Install to Active Threat

• Deploy OpenCanary to Catch Attackers Inside Your Network

• AIDE File Integrity Monitoring: Detect Unauthorized Changes on Linux

View all
#intrusion-prevention3 articles

• CrowdSec: Deploy a Community-Powered Intrusion Prevention System

• Fail2ban: Automated Brute Force Protection for Linux Servers

• Build a Collaborative IPS with CrowdSec

View all
#Logging3 articles

• Sysmon and Windows Event Forwarding: Enterprise-Grade

• FortiAnalyzer Log Forwarding and Compliance Reports

• Build a Centralized Log Management System with Loki and Grafana

View all
#endpoint-security3 articles

• Sysmon and Windows Event Forwarding: Enterprise-Grade

• Velociraptor DFIR Setup, Hunts, and Forensic Collection

• Osquery Endpoint Visibility & Threat Hunting

View all
#Security Baseline3 articles

• The Microsoft 365 Security Baseline Every Small Business Should Have

• Security Baseline Hardening: CIS Controls Implementation

• Microsoft 365 Security Baseline Implementation

View all
#homelab3 articles

• Deploying Vaultwarden: A Self-Hosted Password Manager

• MITRE Caldera: Building an Adversary Emulation Lab

• Headscale: Self-Hosted Tailscale Control Server for Zero-Trust Mesh VPN

View all
#SOAR3 articles

• How to Configure Microsoft Sentinel Analytics Rules

• Building a SOAR Platform with Shuffle in Your Homelab

• Azure Sentinel SIEM Implementation

View all

All Tags

#Vulnerability(510)
#CVE(457)
#RCE(377)
#Data Breach(336)
#Supply Chain(290)
#Ransomware(246)
#Cybercrime(228)
#Zero-Day(207)
#WordPress(204)
#Malware(201)
#NVD(175)
#Threat Intelligence(170)
#Critical(165)
#BleepingComputer(164)
#AI Security(158)
#Microsoft(152)
#SQL Injection(138)
#Privilege Escalation(128)
#Web Security(125)
#Security Updates(123)
#Cloud Security(112)
#The Hacker News(109)
#Authentication Bypass(109)
#Windows(107)
#Remote Code Execution(93)
#Law Enforcement(86)
#APT(78)
#CISA KEV(78)
#Healthcare(75)
#Phishing(74)
#PHP(74)
#Security(74)
#Nation-State(69)
#npm(69)
#Russia(68)
#Critical Infrastructure(65)
#AI(65)
#Command Injection(63)
#Privacy(62)
#Google(60)
#Linux(57)
#CISA(56)
#Social Engineering(53)
#Cryptocurrency(53)
#Open Source(52)
#Network Security(52)
#Unauthenticated(52)
#China(51)
#Credential Theft(51)
#Account Takeover(49)
#Espionage(46)
#Patch Tuesday(46)
#Active Exploitation(46)
#Path Traversal(46)
#ShinyHunters(44)
#File Upload(43)
#IoT(42)
#Router(42)
#Plugin Vulnerability(40)
#GitHub(39)
#sentinelone(39)
#automation(39)
#Government(38)
#Cisco(38)
#edr(38)
#SourceCodester(38)
#AWS(37)
#Infostealer(37)
#Fraud(37)
#Android(36)
#XSS(36)
#Critical Vulnerability(36)
#policy(34)
#Fortinet(34)
#DevSecOps(34)
#Docker(34)
#Deserialization(34)
#Buffer Overflow(34)
#OpenAI(33)
#North Korea(32)
#Incident Response(32)
#Botnet(32)
#Anthropic(31)
#Python(31)
#IoT Security(31)
#VPN(31)
#CWE-89(31)
#ICS(30)
#threat-hunting(30)
#ClickFix(29)
#TeamPCP(29)
#Chrome(28)
#Extortion(28)
#OS Command Injection(28)
#Apple(27)
#firewall(27)
#deployment(27)
#detection-rules(27)
#FBI(26)
#Agentic AI(26)
#Developer Security(26)
#Web Application(26)
#api(26)
#Authorization Bypass(26)
#Mobile Security(25)
#DOJ(25)
#SSRF(25)
#Azure(25)
#macOS(24)
#WooCommerce(24)
#incident-response(24)
#Code Injection(23)
#CVSS 9.8(23)
#Enterprise Security(22)
#Sandbox Escape(22)
#KEV(22)
#SecurityWeek(22)
#Ukraine(21)
#Kubernetes(21)
#Browser Security(21)
#Email Security(21)
#Node.js(21)
#API Security(21)
#Iran(20)
#CI/CD(20)
#E-Commerce(19)
#Container Security(19)
#Homelab(19)
#Cybersecurity(18)
#Third-Party Risk(18)
#Oracle(18)
#Claude(18)
#SonicWall(18)
#D-Link(18)
#OT Security(18)
#Java(18)
#Takedown(17)
#Prompt Injection(17)
#Patch Now(17)
#Compliance(17)
#Identity Security(17)
#Backdoor(17)
#SIEM(17)
#PowerShell(17)
#Telecom(16)
#PII(16)
#DDoS(16)
#Salesforce(16)
#JavaScript(16)
#GitHub Actions(16)
#Langflow(16)
#Plugin Security(16)
#Endpoint Security(16)
#CVSS 10(16)
#IBM(16)
#Access Control(16)
#forensics(16)
#Perl(16)
#Funding(15)
#OAuth(15)
#Patch(15)
#iOS(15)
#DeFi(15)
#PyPI(15)
#GDPR(15)
#Open Source Security(15)
#Adobe(15)
#MCP(15)
#VMware(15)
#Stored XSS(15)
#Insider Threat(14)
#Education(14)
#Identity Theft(14)
#Europol(14)
#Firmware(14)
#Blockchain(14)
#Microsoft 365(14)
#Active Directory(14)
#SD-WAN(14)
#SiYuan(14)
#mitre-attack(14)
#Dark Web(13)
#FortiGate(13)
#HIPAA(13)
#Netherlands(13)
#Security Research(13)
#Artificial Intelligence(13)
#Zero Trust(13)
#cPanel(13)
#DNS(13)
#CMS(13)
#CWE-78(13)
#Weekly Recap(12)
#General(12)
#Cryptography(12)
#Router Security(12)
#NGINX(12)
#authentication(12)
#Ubiquiti(12)
#TLS(12)
#Hardening(12)
#Information Disclosure(12)
#Database(12)
#Tenda(12)
#High(12)
#Totolink(12)
#Enterprise(11)
#Japan(11)
#RaaS(11)
#ChatGPT(11)
#Startup(11)
#France(11)
#Worm(11)
#The Record(11)
#Use-After-Free(11)
#smb(11)
#Hugging Face(11)
#SOC(11)
#Ivanti(11)
#UK(11)
#Memory Corruption(11)
#UniFi(11)
#AI Agents(11)
#Joomla(11)
#Session Hijacking(11)
#Authentication(11)
#Vulnerability Research(10)
#Money Laundering(10)
#Vulnerability Management(10)
#Actively Exploited(10)
#Qilin(10)
#BEC(10)
#Magento(10)
#Encryption(10)
#Data Protection(10)
#Regulation(10)
#Supply Chain Security(10)
#LLM(10)
#RAT(10)
#Next.js(10)
#SharePoint(10)
#Vercel(10)
#Entra ID(10)
#SAP(10)
#TanStack(10)
#Manufacturing(10)
#Red Hat(10)
#SSH(10)
#Missing Authorization(10)
#Plugin(10)
#Dell(10)
#OpenClaw(9)
#n8n(9)
#DevOps(9)
#canada(9)
#Data Exfiltration(9)
#Zimbra(9)
#Dark Reading(9)
#Exploit(9)
#Source Code(9)
#Physical Security(9)
#Patient Data(9)
#KrebsOnSecurity(9)
#Backup(9)
#Identity(9)
#Retail(9)
#SEC Disclosure(9)
#Personal Data(9)
#Sentencing(9)
#LMS(9)
#Web Server(9)
#DoS(9)
#Exploitation(9)
#Grafana(9)
#IDOR(9)
#AI Safety(9)
#Hardcoded Credentials(9)
#Database Security(9)
#REST API(9)
#code-projects(9)
#CVSS 9.1(9)
#Financial Crime(8)
#APT28(8)
#Infrastructure(8)
#Web Application Security(8)
#Spyware(8)
#PHI(8)
#Veeam(8)
#Cyberattack(8)
#Automotive(8)
#LiteLLM(8)
#WebSocket(8)
#Claude Code(8)
#Weekly Roundup(8)
#Meta(8)
#Apache(8)
#Web Shell(8)
#Machine Learning(8)
#Unauthenticated RCE(8)
#PHP Object Injection(8)
#JWT(8)
#Heap Buffer Overflow(8)
#Networking(8)
#IP Camera(8)
#CIS Benchmarks(8)
#Monitoring(8)
#EU(7)
#Deepfake(7)
#Surveillance(7)
#Developer Tools(7)
#CrowdStrike(7)
#MFA Bypass(7)
#Windows 11(7)
#Samsung(7)
#Interpol(7)
#AI Regulation(7)
#Axios(7)
#Lazarus Group(7)
#Risk Management(7)
#AI Policy(7)
#Microsoft Edge(7)
#Windows Server(7)
#Regulatory Fine(7)
#C2(7)
#Web Hosting(7)
#LLM Security(7)
#PAN-OS(7)
#South Korea(7)
#Self-Hosted(7)
#Brute Force(7)
#Threat Detection(7)
#WhatsApp(7)
#Google Chrome(7)
#MFA(7)
#ColdFusion(7)
#GeoVision(7)
#CWE-94(7)
#Traefik(7)
#Geopolitics(6)
#Vishing(6)
#DeepSeek(6)
#Europe(6)
#Sanctions(6)
#BlackCat(6)
#Workflow Automation(6)
#Federal(6)
#Backup & Replication(6)
#Enterprise Backup(6)
#VS Code(6)
#Shadow AI(6)
#SaaS Security(6)
#Citrix(6)
#Adobe Commerce(6)
#F5(6)
#BIG-IP(6)
#National Security(6)
#Southeast Asia(6)
#Bitcoin(6)
#Crypto(6)
#Pre-Auth(6)
#Supply Chain Attack(6)
#CyberScoop(6)
#NVIDIA(6)
#Credentials(6)
#Patch Management(6)
#Export Controls(6)
#Windows Defender(6)
#Microsoft Teams(6)
#Firefox(6)
#Child Safety(6)
#MSP(6)
#EPMM(6)
#Kernel(6)
#Palo Alto Networks(6)
#Energy Sector(6)
#BitLocker(6)
#Heap Overflow(6)
#PraisonAI(6)
#Vulnerability Disclosure(6)
#Arrest(6)
#Research(6)
#Gitea(6)
#Credential Stuffing(6)
#Check Point(6)
#Australia(6)
#Secrets Management(6)
#Data Exposure(6)
#Signal(6)
#Telegram(6)
#Load Balancer(6)
#Embedded Security(6)
#threat-intelligence(6)
#supply-chain(6)
#GitLab(6)
#Firewall(6)
#CVSS 10.0(6)
#Denial of Service(6)
#Broadcom(6)
#Cross-Site Scripting(6)
#Arbitrary File Write(6)
#SAML(6)
#CWE-287(6)
#Directory Traversal(6)
#Password Reset(6)
#File Deletion(6)
#Arbitrary File Upload(6)
#Wazuh(6)
#CVSS Critical(6)
#vm2(6)
#Legal(5)
#Data Extortion(5)
#Scattered Spider(5)
#Deepfakes(5)
#Aviation(5)
#Gemini(5)
#Hacktivism(5)
#Telecommunications(5)
#MongoDB(5)
#Cloudflare(5)
#AiTM(5)
#Extradition(5)
#Mandiant(5)
#Data Theft(5)
#CRM(5)
#Bug(5)
#SGLang(5)
#Regulatory(5)
#Financial Services(5)
#Kimwolf(5)
#Unauthorized Access(5)
#Initial Access Broker(5)
#Nation State(5)
#Post-Quantum(5)
#Wiper(5)
#Chainguard(5)
#SBOM(5)
#Germany(5)
#Credential Security(5)
#IAM(5)
#Apache ActiveMQ(5)
#PDF(5)
#EDR Bypass(5)
#Virtualization(5)
#Disaster Recovery(5)
#NIST(5)
#RMM(5)
#Checkmarx(5)
#Password Manager(5)
#Mozilla(5)
#Auth Bypass(5)
#Go(5)
#AI Platform(5)
#Malvertising(5)
#Security Operations(5)
#Security Update(5)
#Network-Security(5)
#Election Security(5)
#PoC(5)
#Rootkit(5)
#Laravel(5)
#LiteSpeed(5)
#OWASP(5)
#ICS Security(5)
#Memory Safety(5)
#social-engineering(5)
#AI Tools(5)
#Outage(5)
#Credential Exposure(5)
#N-able(5)
#zero-trust(5)
#Wordfence(5)
#SSO(5)
#CWE-121(5)
#Ecommerce(5)
#SOHO(5)
#MLflow(5)
#PowerProtect(5)
#Remote Exploit(5)
#CVSS 9.6(5)
#itsourcecode(5)
#cve(5)
#CWE-502(5)
#Template Injection(5)
#Identity Provider(5)
#PKI(5)
#Network Device(5)
#Input Validation(5)
#Knowledge Management(5)
#Hard-Coded Credentials(5)
#Containers(5)
#threat-detection(5)
#blue-team(5)
#Banking(4)
#Threat Actors(4)
#Fintech(4)
#Amazon(4)
#PhaaS(4)
#Guilty Plea(4)
#Spain(4)
#GlassWorm(4)
#Solana(4)
#Hardware Security(4)
#Trivy(4)
#Streaming(4)
#NetScaler(4)
#CVE-2026-3055(4)
#CVE-2025-53521(4)
#California(4)
#European Commission(4)
#TrueConf(4)
#File Transfer(4)
#Software Security(4)
#Windows Update(4)
#DPRK(4)
#Redis(4)
#PostgreSQL(4)
#Penetration Testing(4)
#REvil(4)
#US Government(4)
#Unpatched(4)
#Storm-1175(4)
#Medusa(4)
#Snowflake(4)
#Banking Trojan(4)
#Business Email Compromise(4)
#Detection(4)
#AppSec(4)
#Business Continuity(4)
#BeyondTrust(4)
#Piracy(4)
#Hospitality(4)
#Threat Actor(4)
#JFrog(4)
#Copilot(4)
#Tor(4)
#FTC(4)
#Medtronic(4)
#Robotics(4)
#Canvas(4)
#OFAC(4)
#2FA(4)
#Kerberos(4)
#Corporate Security(4)
#Mini Shai-Hulud(4)
#Financial Security(4)
#Shai-Hulud(4)
#Defense(4)
#Acquisitions(4)
#Governance(4)
#Drupal(4)
#Chromium(4)
#CMS Security(4)
#Social Media(4)
#23andMe(4)
#GlobalProtect(4)
#VPN Security(4)
#Dashlane(4)
#VoIP(4)
#Pakistan(4)
#Cyber Policy(4)
#Rust(4)
#FFmpeg(4)
#SolarWinds(4)
#PeopleSoft(4)
#Enterprise Software(4)
#INC Ransomware(4)
#JetBrains(4)
#Code Execution(4)
#StealC(4)
#Industry News(4)
#Threat Hunting(4)
#ai-security(4)
#Third Party Risk(4)
#Data Security(4)
#Remote Access(4)
#Payment Security(4)
#data-breach(4)
#Apache Tomcat(4)
#ransomware(4)
#vulnerability(4)
#critical(4)
#NASA(4)
#United Kingdom(4)
#Patchstack(4)
#SCADA(4)
#Coolify(4)
#CSRF(4)
#CPAN(4)
#Stack Overflow(4)
#CWE-434(4)
#AJAX(4)
#CWE-269(4)
#Object Injection(4)
#CVSS 9.9(4)
#Education Software(4)
#Unauthenticated Access(4)
#LDAP(4)
#Embedded Device(4)
#SSTI(4)
#CWE-347(4)
#CWE-639(4)
#Image Processing(4)
#Avi Load Balancer(4)
#APSB26-68(4)
#Incus(4)
#OT(4)
#File Write(4)
#Thunderbird(4)
#Network Devices(4)
#MSI(4)
#OIDC(4)
#DFIR(4)
#Conditional Access(4)
#linux(4)
#XDR(4)
#Intune(4)
#device-control(4)
#Verizon(3)
#Antitrust(3)
#DHS(3)
#Trends(3)
#Lapsus$(3)
#Biometrics(3)
#Age Verification(3)
#Italy(3)
#Semiconductor(3)
#Logistics(3)
#Israel(3)
#ALPHV(3)
#Defense Strategy(3)
#Cybercrime Takedown(3)
#MDM(3)
#CVE-2026-2441(3)
#Akira(3)
#AI Infrastructure(3)
#DarkSword(3)
#Web Skimmer(3)
#Hacktivist(3)
#Steganography(3)
#Spear-Phishing(3)
#NCII(3)
#FCC(3)
#CISO(3)
#AI Security Research(3)
#UNC1069(3)
#Hack(3)
#Crypto Heist(3)
#Drift Protocol(3)
#Governance Attack(3)
#Shadowserver(3)
#Texas(3)
#Zendesk(3)
#Black Hat(3)
#GandCrab(3)
#DNS Hijacking(3)
#IC3(3)
#Investment Fraud(3)
#Ninja Forms(3)
#cyber insurance(3)
#Passport Data(3)
#Acrobat Reader(3)
#Online Safety Act(3)
#Productivity(3)
#Mirai(3)
#Water Security(3)
#Performance(3)
#CVE-2026-3844(3)
#ADT(3)
#Bitwarden(3)
#Exchange Server(3)
#Consumer Security(3)
#Have I Been Pwned(3)
#Zero-Click(3)
#Medical Devices(3)
#Crypto Fraud(3)
#ConnectWise(3)
#OpenEMR(3)
#Instructure(3)
#Trellix(3)
#RansomHouse(3)
#WHM(3)
#CCPA(3)
#Higher Education(3)
#CI/CD Security(3)
#Windows Security(3)
#Venture Capital(3)
#FortiSandbox(3)
#Pharmaceutical(3)
#Foxconn(3)
#Poland(3)
#Exchange(3)
#Source Code Theft(3)
#Responsible Disclosure(3)
#7-Eleven(3)
#Bug Bounty(3)
#Scam(3)
#Industry Analysis(3)
#App Store(3)
#Bulletproof Hosting(3)
#BYOVD(3)
#Consumer Privacy(3)
#Gogs(3)
#Disclosure(3)
#AI Abuse(3)
#Frontier AI(3)
#Domain Controller(3)
#Residential Proxy(3)
#EDR Evasion(3)
#Account Security(3)
#Risk Assessment(3)
#Smart TV(3)
#Vulnerability Scanning(3)
#Serv-U(3)
#ServiceNow(3)
#The Gentlemen(3)
#SocGholish(3)
#Industrial Security(3)
#AI Governance(3)
#Wallet Security(3)
#FortiBleed(3)
#Pig Butchering(3)
#Browser Extension(3)
#Insurance(3)
#Cursor IDE(3)
#India(3)
#Reconnaissance(3)
#CVE-2026-15409(3)
#CVE-2026-15410(3)
#Cursor(3)
#OpenSSL(3)
#Africa(3)
#Machine Learning Security(3)
#Arista(3)
#Autonomous Attacks(3)
#malware(3)
#Webmail(3)
#Business Intelligence(3)
#phishing(3)
#MITM(3)
#open-source(3)
#Trezor(3)
#Industrial(3)
#aws(3)
#rce(3)
#TikTok(3)
#COPPA(3)
#ATF(3)
#DevOps Security(3)
#PaperCut(3)
#CVE-2026-81578(3)
#CVE-2026-82078(3)
#PrestaShop(3)
#Elementor(3)
#Statistics(3)
#M365(3)
#Notepad++(3)
#Google TAG(3)
#End of Life(3)
#CVE-2026-1731(3)
#ZKTeco(3)
#CORS(3)
#Session Management(3)
#Data Domain(3)
#Apache Airflow(3)
#Remote Exploitation(3)
#WebSphere(3)
#Remote Management(3)
#Improper Authentication(3)
#Missing Authentication(3)
#CodeIgniter(3)
#MySQL(3)
#Admin Panel(3)
#reserved(3)
#Server-Side Request Forgery(3)
#LibRaw(3)
#RAW Image(3)
#Reverse Proxy(3)
#Domain User(3)
#CWE-284(3)
#Spring Security(3)
#Spinnaker(3)
#CWE-22(3)
#Out-of-Bounds(3)
#ZITADEL(3)
#Unbound(3)
#LXD(3)
#Canonical(3)
#Prototype Pollution(3)
#MiTM(3)
#Header Injection(3)
#Apache Camel(3)
#SAIL(3)
#CWE-798(3)
#Server Administration(3)
#Apache MINA(3)
#authentik(3)
#CWE-306(3)
#GitOps(3)
#Injection(3)
#OpENer(3)
#EtherNet/IP(3)
#CIP(3)
#migration-planner(3)
#Backup Security(3)
#Termix(3)
#Broken Access Control(3)
#HTML Injection(3)
#OAuth2(3)
#ERP(3)
#End of Life Software(3)
#Grav CMS(3)
#OSINT(3)
#hulumi(3)
#FortiOS(3)
#Router Vulnerability(3)
#vulnerability-scanning(3)
#IDS(3)
#intrusion-detection(3)
#intrusion-prevention(3)
#Logging(3)
#endpoint-security(3)
#Security Baseline(3)
#homelab(3)
#SOAR(3)