Cyera has announced a $1 billion acquisition of Oasis Security, signaling one of the largest deals in the data security space this year and a clear bet that the next frontier of...
WordPress released version 7.0.4 on Wednesday to address a high-severity remote code execution vulnerability tracked as CVE-2026-65640, carrying a CVSS score of 8.8. The flaw allow...
Hackers began exploiting a critical Adobe Commerce vulnerability almost immediately after Adobe published its patch advisory, according to webstore security firm Sansec. Tracked as...
A series of severe vulnerabilities discovered in the browser extension powering Belgium's national electronic identification (eID) system could allow attackers to execute arbitr...
Twenty-one cybersecurity-related merger and acquisition deals were announced in July 2026, signaling continued consolidation across identity protection, AI-driven detection, and ne...
Threat actors are actively weaponizing a critical Microsoft SharePoint authentication bypass vulnerability, CVE-2026-55040, following the public release of a proof-of-concept (PoC)...
SAP has rolled out emergency patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary c...
Microsoft's July Patch Tuesday addressed CVE-2026-55040, a SharePoint vulnerability rooted in weak authentication that allows remote, unauthenticated attackers to bypass securit...
The FBI has issued a new public alert warning that threat actors are increasingly using social engineering and cyber intrusion techniques to compromise social media accounts belong...
Adobe has rolled out emergency patches addressing multiple critical security vulnerabilities across ColdFusion, Commerce, and Campaign Classic that could allow attackers to execute...
A malicious SIM card can run attacker-controlled code directly inside the cellular modems powering electric-vehicle chargers, industrial routers, and automotive telematics units, a...
The Gunra ransomware-as-a-service (RaaS) operation has emerged as a significant threat to critical infrastructure organizations, leveraging leaked Conti source code and weaponizing...
Poland's CERT Polska has disclosed a previously unknown cyberattack that disrupted a combined heat and power (CHP) plant supplying heat to roughly 50,000 residents during last wint...
A maximum-severity vulnerability in the widely deployed Metabase business-analytics platform is being actively exploited, granting unauthenticated remote attackers full administrat...
Security researcher James Arnott, founder of cybersecurity firm Bay Area Labs, disclosed severe vulnerabilities in the Connective digital identity system, a browser extension devel...
PortSwigger researcher Gareth Heyes presented a new class of CSS-based webmail attacks at Black Hat USA 2026, demonstrating how content inside an email can escape its message bound...
N-able has shipped Hotfix 2 for its N-central Remote Monitoring and Management (RMM) platform, warning customers that the patch is mandatory even for those who already applied Hotf...
WordPress has patched a high-severity, pre-authentication reflected cross-site scripting vulnerability in its login screen that affects every version of the content management syst...
Arctic Wolf Labs has revealed a widespread adversary-in-the-middle (AitM) phishing campaign targeting Microsoft 365 accounts at organizations across healthcare, education, manufact...
Connor Riley Moucka, of Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy charges stemming from a massive 2024 extortion campaign that compromised more than 1...
When Bob Lord joined the Democratic National Committee as its first-ever chief security officer in the aftermath of the 2016 election breach, he inherited an organization still ree...
Two critical security vulnerabilities in Paperclip, an open-source control plane for managing teams of AI agents, could allow attackers to execute arbitrary host commands on a netw...
Three major software vendors — Veeam, HashiCorp, and the Django Software Foundation — released patches on August 5, 2026, addressing 11 vulnerabilities across Terraform MCP Server,...
A critical vulnerability in Gitea, the self-hosted Git platform, allows unauthenticated attackers to read any file the service account can access—no login or repository write acces...
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has evolved into a more dangerous offering, adding support for device code phishing to its existing arsenal ...
cPanel has shipped an emergency patch for a critical privilege-escalation vulnerability that lets authenticated hosting customers execute arbitrary SQL commands with full database-...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog fo...
Attackers are rapidly abandoning traditional credential-stealing campaigns in favor of social engineering techniques that sidestep multi-factor authentication and leave minimal for...
Over the weekend, N-able disclosed a critical authentication bypass vulnerability tracked as CVE-2026-18577 affecting its Remote Monitoring and Management (RMM) platform. The flaw ...
Researchers at Palo Alto Networks' Unit 42 have uncovered three attack paths against Chrome's Google Password Manager cloud authenticator that could allow malware running as a stan...
USA Fencing, the national governing body for the sport and the organization responsible for fielding Team USA's Olympic and Paralympic fencing squads, has deployed automated ide...
Device code phishing, the abuse of the OAuth 2.0 device authorization grant to hijack access tokens, has escalated from a niche red-team technique into an industrial-scale threat i...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly disclosed flaw in Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited V...
Ruby on Rails has shipped emergency patches for a critical Active Storage vulnerability, tracked as CVE-2026-66066 with a CVSS score of 9.5, that enables unauthenticated attackers ...
Broadcom has shipped urgent security updates to address five vulnerabilities affecting VMware ESX, vCenter Server, Workstation, and Fusion, three of which carry critical severity r...
Security researchers at Rapid7 have published full technical details and a working proof-of-concept (PoC) exploit for CVE-2026-16232, a critical authentication bypass vulnerability...
Security researcher Aleksandr Krasnov has spotlighted a growing blind spot in cloud environments: dormant non-human identities (NHIs) that retain trust paths long after they should...
Thousands of internet-exposed Baseboard Management Controllers (BMCs) and similar remote hardware management interfaces are vulnerable to offline password-cracking attacks, and thr...
Cybersecurity researchers at Israeli firm Lava have identified more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing the Intelligent Platform Manage...
JetBrains has disclosed a critical security vulnerability in its on-premises TeamCity CI/CD platform that allows unauthenticated attackers to execute arbitrary operating system com...
A class of vulnerabilities known as 'Confused Deputy' flaws continues to plague major cloud platforms, including Google Cloud and Microsoft Azure, according to researchers tracking...
A new investigation from CTM360, published via The Hacker News, reveals that insurance-focused phishing operations have evolved beyond traditional credential harvesting into real-t...
Security researchers H0j3n and Aniq Fakhrul have publicly released a working exploit, dubbed Certighost, that allows a low-privileged Active Directory user to obtain a certifica...
Microsoft has patched a critical configuration flaw in Azure Automation that, combined with a chain of code vulnerabilities, could have allowed attackers to take over identities be...
Cryptocurrency holders are increasingly being targeted through physical-world coercion rather than purely digital exploits, according to a new report from blockchain security audit...
AI agent security is rapidly maturing through a familiar enterprise cycle: adoption, visibility, and finally, control. But as organizations discover, enforcing least privilege for ...
Google has introduced a password recovery method that lets users regain access to their accounts by recording a short selfie video. The biometric verification system, detailed by A...
Qualys has disclosed a nine-year-old Linux kernel vulnerability, tracked as CVE-2026-64600 and nicknamed RefluXFS, that enables unprivileged local users to overwrite root-owned fil...
Check Point has shipped emergency security updates to remediate multiple high-severity flaws affecting its Security Management and Multi-Domain Security Management (MDSM) products,...
A high-severity path traversal vulnerability in the open-source Windmill developer platform is being actively exploited in the wild, according to threat intelligence from VulnCheck...
German and US law enforcement have dismantled the core infrastructure of Kratos, a phishing-as-a-service kit investigators describe as one of the most widely used criminal phishing...
Threat actors affiliated with the Qilin (also known as Agenda) ransomware-as-a-service (RaaS) operation have been weaponizing a now-patched high-severity flaw in Palo Alto Networks...
Owen Flowers, 18, and Thalha Jubair, 20, members of the Scattered Spider cybercrime group, were each sentenced to five and a half years at Woolwich Crown Court on 16 July 2026 for ...
A serious unpatched vulnerability in SharkNinja robot vacuums allows attackers to extract device certificates from the hardware and use them to issue commands on other Shark vacuum...
Identity-based attacks have dethroned vulnerability exploits as the leading root cause of ransomware intrusions, marking a significant shift in attacker tradecraft, according to re...
A single misconfiguration handed French security firm Lexfo an intelligence windfall. During a routine internet scan in late April 2026, researchers found an attacker-controlled ho...
GitHub has officially released npm 12, the latest version of the world's most widely used JavaScript package manager, with a major security-focused overhaul that disables install s...
AI-powered attacks have compressed the attacker's timeline from days to minutes. Using models like "Mythos," adversaries generate tailored phishing bait, identify high-value target...
A sophisticated phishing campaign is weaponizing the names of well-known consumer brands to lure marketing professionals into surrendering their Google Workspace credentials. Resea...
A new Microsoft 365 device-code phishing campaign observed between late June and early July 2026 is leveraging a reusable attack framework dubbed DEBULL to hijack enterprise accoun...
BeyondTrust has rolled out security updates to remediate four critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) appliances, two of which carry ...
Threat actors began probing a critical security flaw in Gitea Docker images just 13 days after public disclosure, according to cloud security firm Sysdig. Tracked as CVE-2026-20896...
Cisco Talos researchers have uncovered a phishing-as-a-service (PhaaS) platform named “ARToken” that operates as an affiliate of the EvilTokens ecosystem, exposing a sophisticated ...
A new macOS information stealer dubbed PamStealer has been identified by Jamf Threat Labs, employing a multi-stage infection chain designed to harvest login credentials, browser da...
Kaspersky researchers have uncovered a sophisticated new malware dubbed Umbrij, attributed to the advanced persistent threat group ToddyCat, which leverages the Google API and OAut...
Enterprise identity lifecycle management was architected around a human employee with an HR record, a reporting manager, and a defined departure date. AI agents possess none of the...
Cybersecurity researchers at Huntress have uncovered a massive, ongoing automated password spray campaign targeting Microsoft's Azure command-line interface (CLI), generating more ...
An unknown threat actor is actively exploiting CVE-2026-48558, a maximum-severity (CVSS 10.0) authentication bypass flaw in SimpleHelp's OpenID Connect (OIDC) flow, to deploy two p...
Critical and high-severity vulnerabilities in Daktronics controllers could allow remote attackers to tamper with highway signs, electronic scoreboards, and digital billboards world...
WhatsApp, the Meta-owned messaging platform used by more than three billion people, officially began global username reservations on Monday. The new optional feature allows users t...
The public-key cryptography protecting today's credentials and encrypted data faces an expiration date. While no existing machine can crack RSA or elliptic curve cryptography, quan...
Japanese telecommunications giant KDDI Corporation has disclosed a major data breach affecting up to 14.22 million email accounts across six domestic internet service providers. Th...
Ukraine's Security Service (SSU), working alongside the U.S. Federal Bureau of Investigation (FBI), has uncovered a long-running cyber espionage campaign attributed to Russian inte...
Two key members of the prolific cybercrime group Scattered Spider pleaded guilty on the opening day of their six-week trial at a UK court. Thalha Jubair, 20, of East London, and 18...
A Russian-speaking initial access broker (IAB) has been linked to a massive credential-harvesting campaign called FortiBleed, which has compromised over 430,000 FortiGate firewalls...
Market intelligence platform Klue has confirmed a security incident in which attackers exploited a compromised legacy credential to steal OAuth tokens, gaining access to multiple c...
CISA has issued an urgent advisory urging Fortinet customers to secure their FortiGate appliances against an ongoing malicious campaign dubbed FortiBleed, which has already comprom...
When an autonomous AI agent interacts with a company's core intellectual property, most security teams cannot instantly name the person who authorized it. The rush to deploy intern...
Organizations now manage thousands of human and non-human identities spread across cloud services, SaaS applications, endpoints, and remote environments. As hybrid work, BYOD polic...
A new analysis of 3,000 organizational attack surfaces reveals that unnecessary internet-facing services remain the weakest link in enterprise defense. Intruder's 2026 Attack Surfa...
Security researchers at Zimperium's zLabs have uncovered a new Android banking trojan dubbed Rokarolla, named after its command-and-control infrastructure. The malware targets 217 ...
The UK government will require anyone opening a new social media account to verify their age by uploading government-issued ID or passing a facial age scan, under regulations annou...
A critical vulnerability in SimpleHelp remote management software, tracked as CVE-2026-48558, enables unauthenticated attackers to create privileged Technician accounts on servers ...
Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a high-severity authentication bypass vulnerability (CVSS 7.8) affecting the GlobalProtect VPN portal and gat...
Ezekiel Dean Potter, a 34-year-old former senior IT support specialist for Iowa's Saydel Community School District, has been sentenced to 21 months in federal prison for a sustaine...
Splunk has rolled out emergency security patches for a critical vulnerability in Splunk Enterprise that allows remote attackers to execute arbitrary code without any authentication...
The Chinese state-linked espionage group "Velvet Ant" maintained undetected access to a large organization's critical infrastructure for an extraordinary 10 years, according to res...
A China-nexus advanced persistent threat tracked as Velvet Ant by incident response firm Sygnia maintained covert access to a target network for nearly a decade by compromising the...
Security researchers at application security firm Aikido have disclosed a severe authentication bypass vulnerability in phpBB, the widely used open-source forum platform, that h...
South Korea's Personal Information Protection Commission (PIPC) has imposed a record 624.7 billion won ($409 million) fine on Coupang, the country's largest online retailer, over a...
Fortinet, Ivanti, and SAP have rolled out urgent security updates addressing multiple critical vulnerabilities that could enable arbitrary code execution, authentication bypass, an...
Hackers are actively exploiting a critical unauthenticated remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin to seize full control of vulnerable w...
Cisco has released a patch for a server-side request forgery (SSRF) vulnerability in Unified Communications Manager (Unified CM) and its Session Management Edition that allows an u...
A single leftover debug flag in production builds of several Microsoft 365 Android applications disabled a critical security check, allowing any app installed on the same device to...
Cybersecurity researchers have disclosed a critical one-click attack chain that abuses Microsoft Visual Studio Code (VS Code) webviews to steal fully scoped GitHub OAuth tokens. Di...
Enterprise identity and access management is approaching a structural breaking point. As organizations scale, identity data fragments across thousands of applications, decentralize...
Cybersecurity researchers at Huntress have disclosed an unpatched vulnerability in the Windows "search:" URI handler that can be weaponized to leak a user's NTLMv2 hash to a remote...
Acer has confirmed it is actively developing patches for two maximum-severity zero-day vulnerabilities impacting its Wave 7 mesh routers. Both flaws were reported by independent se...
Attackers have hijacked multiple high-value Instagram accounts by exploiting Meta's AI-powered support assistant, tricking it into transferring ownership using deepfake selfie vide...
Password manager Dashlane has disclosed a brute-force security incident in which encrypted password vaults belonging to fewer than 20 personal plan subscribers were downloaded by a...
More than 30 npm packages under the @redhat-cloud-services namespace were compromised in a sophisticated supply‑chain attack that delivered a new variant of the Shai‑Hulud credenti...
Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a medium-severity authentication bypass vulnerability (CVSS 7.8) affecting PAN-OS and Prisma Access GlobalPro...
A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, enabling authenticated users to execute arbitrary code on affected serv...
Multi-factor authentication (MFA) was designed to close a critical gap in identity security by requiring a second factor beyond passwords. However, attackers have developed a techn...
The FBI has issued a critical advisory regarding Kali365, a Telegram-based Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to compromise Microsoft 365 accounts b...
A threat actor recently obtained an AWS access key cached on a developer's workstation through standard browser behavior—no misconfiguration or policy violation required. This sing...
Organizations are dramatically increasing investments in AI agent identity management as enterprise deployments accelerate, according to new research from Omdia. The study reveals ...
In a concentrated 48-hour window, threat actors launched coordinated attacks against npm, PyPI, and Docker Hub, marking a significant escalation in software supply chain aggression...
Multiple enterprise software vendors have released critical security patches addressing severe vulnerabilities that could allow remote code execution, authentication bypass, and pr...
Twin brothers Muneeb and Sohaib Akhter, both 34, have been accused of destroying 96 databases holding US government information within minutes of being fired from their Washington,...
Security researchers have identified a new self‑propagating threat, named PCPJack, that behaves like a worm while simultaneously purging systems infected by the earlier TeamPCP mal...
A federal jury in Virginia has convicted 39-year-old Richmond resident James E. Thornton on multiple charges stemming from a 2023 cyber intrusion that resulted in the deletion of 9...
Cybersecurity researchers have disclosed a previously unknown Linux backdoor called PamDOORa that is being actively advertised on the Russian cybercrime forum Rehub for $1,600 by a...
Security analysts have uncovered a sophisticated intrusion campaign leveraging the CloudZ remote access trojan (RAT) alongside a previously undocumented plugin called Pheno to targ...
Security researchers have uncovered a sophisticated cyberattack campaign leveraging the Windows Phone Link application to steal text messages and circumvent two-factor authenticati...
A sophisticated phishing campaign is leveraging Google’s sponsored search ads to mimic the login page of ManageWP, GoDaddy’s platform for centrally managing large fleets of WordPre...
A new proof‑of‑concept (PoC) published by security researcher Alex Chen of CyberX Labs shows that Microsoft Edge stores user passwords in plaintext within the browser’s process mem...
Progress Software has released urgent updates for MOVEit Automation (formerly Central) that address two security flaws, the most severe of which is a critical authentication bypass...
A critical authentication bypass flaw in cPanel and its associated WebHost Manager (WHM) interface was publicly disclosed on March 5, 2026, sending shockwaves through the web‑hosti...
Fraudsters are not breaking into credit unions with zero‑days or ransomware; they are exploiting the normal loan origination workflow. Flare’s threat‑intelligence team uncovered a ...
Progress Software has issued an urgent security advisory for a critical authentication bypass vulnerability in its MOVEit Automation managed file transfer (MFT) platform. Tracked a...
Security researchers have flagged a new iteration of the consent‑phishing tool known as ConsentFix, now labeled v3, which dramatically expands the scale and automation of attacks a...
cPanel and its WebHost Manager (WHM) product line contain a critical authentication flaw that could allow a remote attacker to bypass login controls and gain full control of the ho...
Tycoon, a well‑known phishing collective that has long abused two‑factor authentication (2FA) bypass tricks, has quietly shifted to a new attack vector: OAuth 2.0 device‑code phish...
Security researchers have linked a new wave of cyber‑attacks to Russia’s military intelligence, specifically the APT groups tied to the GRU, which are actively exploiting known vul...
Worldcoin’s World ID initiative, built by Tools for Humanity, is deploying a biometric authentication system based on iris scanning to assign a unique human identity to every AI ag...
Google has announced significant changes to its Android app distribution model, implementing mandatory developer verification for all apps published on Google Play Store. The new r...
Even major online services that pride themselves on seamless login experiences are quietly exposing sensitive user data through SMS sign‑in links. Security researchers analyzing th...
Google has officially announced its Android developer verification program will feature both free and paid tiers, marking a significant shift in how developers are authenticated be...
Google has publicly pushed back against viral claims circulating online that all 2.5 billion Gmail accounts have been compromised in a sweeping security incident. The rumors, which...
Clorox has filed a lawsuit against a service desk vendor following a 2023 cybersecurity breach that cost the company approximately $380 million. The legal action centers on allegat...
A coordinated phishing operation attributed to the threat group 0ktapus has ensnared more than 130 organizations across multiple industries, according to researchers at Threatpost....