WordPress fixes a critical unauthenticated path traversal flaw that can load local PHP files and, on some servers, enable ...
Microsoft disrupted EvilTokens after it was linked to more than 12,000 compromised inboxes across over 10,000 organizations.
AI agents can chain credentials and tools to reach beyond direct permissions, as a Hugging Face evaluation showed.
Check Point fixed a Management Server flaw exploited in targeted July attacks that can run scripts without login.
Malicious npm package tw-pkgprobe-7731 targets Twilio developer environments and can exfiltrate credentials and environment ...
Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes.
BigDiskBuster can block Microsoft Defender updates by filling disk space, leaving detection content stale; no patch or advisory exists.
Bifrost CVE-2026-90898 enables unauthenticated command execution with management auth disabled; transports/v2.1.0 fixes the flaw.
A Mac Muse flaw lets malware running as the logged-in user reroute dictation, inject instructions, and steal the assistant's ...
DORA’s second year shifts focus to proving ICT controls work, with network evidence supporting monitoring, detection, and incident response.
SharePoint CVE-2026-65660 enables authenticated RCE; Microsoft patched it on August 11, and no in-the-wild exploitation is reported.
CISA added Zyxel CVE-2026-7273 to KEV after active exploitation, while Arctic Wolf reported attacks on a Veeam Windows flaw.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results