Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
A CVSS 10.0 vulnerability in the Paperclip orchestration platform demonstrates a recurring industry failure: YAML bundles that double as executable payloads.
Kaspersky's GReAT team reports 75 million attacks blocked in APAC during the first half of 2026, alongside warnings over rising global supply chain threats.
CrowdStrike's latest Threat Hunting Report traces a multiyear shift from conventional intrusions toward attacks that exploit trusted identities, cloud services, AI systems, and software dependencies.
In a Ghostjacking attack, an AI agent executes instructions planted in the log that records a blocked request word for word.
Tenet Security showed how a publicly exposed error-tracking credential and an MCP integration chain into remote code ...
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without ...
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under ...
QuickFox VPN users might be at risk. Researchers discovered that attackers trojanized the software's Windows installer for ...
Reports from Cisco Talos and CrowdStrike provide real-world insights into how AI is evolving attackers’ tradecraft and ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results