Cyera has announced a $1 billion acquisition of Oasis Security, signaling one of the largest deals in the data security space this year and a clear bet that the next frontier of...
Beacon, a UK-based customer relationship management (CRM) provider serving the non-profit sector, has disclosed that a data breach impacting more than 1,000 charities stemmed from ...
Google Cloud has published an updated roadmap for migrating its infrastructure to post-quantum cryptography (PQC), targeting full readiness by 2029 with some work extending into th...
Security teams across the globe are scrambling to contain active exploitation of CVE-2026-59310, a critical vulnerability in VMware vCenter Server that threat actors began weaponiz...
Twenty-one cybersecurity-related merger and acquisition deals were announced in July 2026, signaling continued consolidation across identity protection, AI-driven detection, and ne...
Israeli venture capital firm Team8 has closed $365 million in fresh capital, bringing its total assets under management to roughly $2 billion since its 2014 founding. According to ...
SAP has rolled out emergency patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary c...
Walmart, the world's largest retailer by revenue, has overhauled its security operations center (SOC) by leaning into a culture-first model that prioritizes psychological safety, t...
Adobe has rolled out emergency patches addressing multiple critical security vulnerabilities across ColdFusion, Commerce, and Campaign Classic that could allow attackers to execute...
Adobe released security updates on Tuesday addressing more than 50 vulnerabilities across its product portfolio, including critical-severity flaws in ColdFusion, Campaign Classic, ...
A financially motivated threat cluster tracked as UNC6671 has intensified its voice phishing (vishing) operations against enterprise employees in financial services, private equity...
A critical 18-year-old use-after-free vulnerability in the Linux kernel's SCTP networking stack, dubbed "SCTPhantom" and tracked as CVE-2026-64564, can grant local users root privi...
Connor Riley Moucka, of Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy charges stemming from a massive 2024 extortion campaign that compromised more than 1...
A newly disclosed Linux kernel vulnerability dubbed Zapscape (CVE-2026-64561) could allow an attacker with kernel-level access inside an L1 guest virtual machine t...
Three major software vendors — Veeam, HashiCorp, and the Django Software Foundation — released patches on August 5, 2026, addressing 11 vulnerabilities across Terraform MCP Server,...
A critical vulnerability in Gitea, the self-hosted Git platform, allows unauthenticated attackers to read any file the service account can access—no login or repository write acces...
GitGuardian researchers have uncovered a significant exposure of n8n workflow automation API tokens, identifying 4,576 unique credentials across 1,255 hostnames in public GitHub co...
Google has removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after Pillar Security demonstrated that a malicious public GitHub issue could be ...
cPanel has shipped an emergency patch for a critical privilege-escalation vulnerability that lets authenticated hosting customers execute arbitrary SQL commands with full database-...
The Police National Legal Database (PNLD), a service that provides legal information and products to UK police forces and criminal justice organisations, has confirmed a data breac...
Adobe has rolled out emergency security updates to address a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise marketing automation platform, that could allo...
Ruby on Rails maintainers have shipped emergency patches for a critical vulnerability, tracked as CVE-2026-66066 with a CVSS score of 9.5, that could let unauthenticated attackers ...
A now-patched vulnerability in Microsoft Azure Cosmos DB could have granted attackers full read and write access to databases across customer tenants, according to cloud securit...
Check Point Software Technologies has unveiled what it calls the industry's first AI Network Firewall, a new class of network security designed to inspect, detect, and govern AI-dr...
Ruby on Rails has shipped emergency patches for a critical Active Storage vulnerability, tracked as CVE-2026-66066 with a CVSS score of 9.5, that enables unauthenticated attackers ...
Broadcom has shipped urgent security updates to address five vulnerabilities affecting VMware ESX, vCenter Server, Workstation, and Fusion, three of which carry critical severity r...
Security researcher Aleksandr Krasnov has spotlighted a growing blind spot in cloud environments: dormant non-human identities (NHIs) that retain trust paths long after they should...
Cybersecurity researchers at Israeli firm Lava have identified more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing the Intelligent Platform Manage...
Microsoft has rolled out a new lineup of AI-powered security products designed to help enterprise defenders detect, investigate, and respond to threats at scale. The announcement, ...
A class of vulnerabilities known as 'Confused Deputy' flaws continues to plague major cloud platforms, including Google Cloud and Microsoft Azure, according to researchers tracking...
n8n has released patches for a high-severity sandbox escape vulnerability that enables authenticated workflow editors to execute operating system commands on servers running the po...
GitHub has rolled out a new cooldown mechanism in Dependabot that forces the automated dependency-management tool to wait at least three days after a package release is published b...
Security researcher depthfirst published working exploit code on July 24 for a GitLab remote code execution flaw that GitLab quietly patched on June 10 without filing it as a secur...
Two critical command-injection vulnerabilities in Bing Images allowed specially crafted SVG files to execute arbitrary code as NT AUTHORITY\SYSTEM on Microsoft's production image-p...
Microsoft has patched a critical configuration flaw in Azure Automation that, combined with a chain of code vulnerabilities, could have allowed attackers to take over identities be...
Qualys has disclosed a nine-year-old Linux kernel vulnerability, tracked as CVE-2026-64600 and nicknamed RefluXFS, that enables unprivileged local users to overwrite root-owned fil...
A high-severity path traversal vulnerability in the open-source Windmill developer platform is being actively exploited in the wild, according to threat intelligence from VulnCheck...
A single invisible comment embedded in an Azure DevOps pull request can silently hijack a reviewer's AI coding agent, steering it into projects the attacker has no permission to ac...
Apple has resolved a critical privacy flaw in its Hide My Email service that silently exposed users' real email addresses in mail transfer logs, effectively defeating the feature's...
Threat actors are weaponizing a severe sandbox escape vulnerability in the ServiceNow AI Platform, enabling unauthenticated attackers to execute arbitrary code on vulnerable instan...
HollowGraph, a newly documented malware toolkit, is leveraging a compromised Microsoft 365 account's calendar as a two-way dead-drop for command-and-control (C&C) communication, ac...
A newly uncovered espionage implant named HollowGraph is abusing Microsoft 365 calendar infrastructure as a covert command-and-control channel, smuggling both operator instructions...
F5 has released patches for a critical vulnerability in the NGINX web server, tracked as CVE-2026-42533, that allows remote unauthenticated attackers to trigger a heap buffer overf...
Researchers at QiAnXin's XLab have documented a new Go-language botnet called NadMesh that emerged in early July 2026 and is actively scanning the public internet for exposed AI in...
Google Cloud is rolling out an 'agentic defense' strategy that folds key capabilities from its Wiz acquisition into a unified platform designed to automate threat detection and rem...
A serious unpatched vulnerability in SharkNinja robot vacuums allows attackers to extract device certificates from the hardware and use them to issue commands on other Shark vacuum...
When a contractor published a public GitHub repository called “Private CISA” on May 15, 2026, it exposed 844 MB of sensitive agency data—including administrative credentials to thr...
Progress Software has issued an urgent warning to ShareFile customers, instructing them to immediately take offline the Windows servers running their Storage Zone Controllers in re...
A critical unpatched vulnerability in XQUIC—Alibaba's open-source QUIC and HTTP/3 library—allows any remote client to crash servers with a tiny burst of legitimate traffic. Dubbed ...
Datadog Security Labs is sounding the alarm over a coordinated series of campaigns that systematically enumerate corporate GitHub organizations, repositories, and user accounts thr...
A single threat actor has reportedly compromised an Amazon Web Services (AWS) environment belonging to a large enterprise customer in just 72 hours, leveraging AI-driven reconnaiss...
Nebula Security has disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel use-after-free vulnerability that lets any local user escalate to full root on unpatched system...
Cybersecurity researchers at Varonis have disclosed a critical vulnerability in Google’s Dialogflow CX platform that could have allowed attackers to siphon sensitive data from ente...
Threat actors began probing a critical security flaw in Gitea Docker images just 13 days after public disclosure, according to cloud security firm Sysdig. Tracked as CVE-2026-20896...
Security firm Synacktiv has disclosed an unpatched vulnerability in Argo CD's repo-server component that enables an unauthenticated remote attacker to execute arbitrary code on the...
Microsoft has moved up its quantum-safe security roadmap, with Azure CTO Mark Russinovich announcing that the Microsoft Quantum Safe Program (QSP) will now target a full transition...
Citrix has released security updates for six vulnerabilities in NetScaler ADC and NetScaler Gateway that could allow attackers to read arbitrary files or trigger denial-of-service ...
Cybersecurity researchers at Huntress have uncovered a massive, ongoing automated password spray campaign targeting Microsoft's Azure command-line interface (CLI), generating more ...
The Russian advanced persistent threat group Gamaredon maintained an aggressive focus on Ukrainian governmental and military institutions throughout 2025, mounting 35 distinct spea...
Uber has appointed Philip Martin as its new Chief Information Security Officer (CISO), tapping a seasoned security leader with deep experience in incident response, threat intellig...
This week's threat landscape blended privacy innovation with two decades of dormant risk. Cloudflare announced a partnership with Google Chrome, Microsoft Edge, and Mozilla Firefox...
Cybersecurity researchers at Novee Security have identified a critical class of CI/CD workflow misconfiguration dubbed "Cordyceps" that exposes more than 300 high-impact GitHub rep...
The U.S. Department of Justice announced on Tuesday the seizure of a cloud computing account operated by subsidiaries of Cambodia-based conglomerate HuiOne Group, a network accused...
Cybersecurity researchers at Zafran Security have disclosed four vulnerabilities in Dify, the open-source agentic workflow platform boasting more than 146,000 GitHub stars, that co...
The enterprise AI risk landscape has fundamentally shifted. Security teams initially focused on employees pasting sensitive data into public AI tools, responding with usage policie...
F5 has released emergency security updates to address two critical vulnerabilities in NGINX Open Source, both carrying a CVSS v4 score of 9.2, that could allow remote unauthenticat...
When an autonomous AI agent interacts with a company's core intellectual property, most security teams cannot instantly name the person who authorized it. The rush to deploy intern...
A cluster of 23 deceptive Chrome browser extensions has been uncovered routing user searches through monetization middleware before delivering results, exposing roughly 758,000 aff...
F5 has issued out-of-band security updates to remediate two critical-severity vulnerabilities in its NGINX web server software that could allow unauthenticated remote attackers to ...
A critical vulnerability in Google Cloud's Vertex AI SDK for Python allowed attackers to hijack machine learning model uploads and execute arbitrary code inside Google's serving in...
A China-linked espionage group tracked as UNC6508 maintained undetected access to North American medical, academic, and military research networks for over a year, quietly siphonin...
Fortinet, Ivanti, and SAP have rolled out urgent security updates addressing multiple critical vulnerabilities that could enable arbitrary code execution, authentication bypass, an...
A clean penetration test report may look reassuring, but security leaders should read it as a warning sign, not a victory lap. According to Autumn Stambaugh and Can Yüceel of Picus...
Cybersecurity researchers at Cyera have disclosed six vulnerabilities in protobuf.js, a widely used JavaScript and TypeScript implementation of Google's Protocol Buffers serializat...
Veeam has shipped an emergency patch for a critical remote code execution vulnerability in its widely deployed Backup & Replication platform. Tracked as CVE-2026-44963, the flaw ca...
ServiceNow disclosed a security incident on June 9, 2026, revealing that attackers exploited an unauthenticated access flaw in a REST API endpoint to query data from hosted custome...
The threat actor tracked as PCPJack has compromised at least 230 cloud servers across Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure, converting them into a ...
Redis has patched a use-after-free vulnerability in its blocking-client code that allows an authenticated user to execute arbitrary OS commands on the host running the database. Tr...
Enterprise identity and access management is approaching a structural breaking point. As organizations scale, identity data fragments across thousands of applications, decentralize...
Cybersecurity researchers at Calif have disclosed a new remote denial-of-service vulnerability dubbed "HTTP/2 Bomb" that affects five major web server platforms: NGINX, Apache HTTP...
Microsoft announced at its Build 2026 developer conference the release of Coreutils for Windows, a package that delivers common Linux command-line utilities as native Windows appli...
Microsoft is actively investigating a widespread service disruption affecting the mail flow pipeline for Exchange Online customers in North America and Germany. The incident, track...
The managed service provider (MSP) cybersecurity landscape is undergoing a significant transformation as traditional vCISO platforms fail to meet the demands of modern security pra...
Sysdig researchers have documented a sophisticated cyberattack where threat actors deployed a large language model (LLM) agent to automate post-exploitation activities following th...
The FBI has issued a critical advisory regarding Kali365, a Telegram-based Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to compromise Microsoft 365 accounts b...
A threat actor recently obtained an AWS access key cached on a developer's workstation through standard browser behavior—no misconfiguration or policy violation required. This sing...
Organizations are dramatically increasing investments in AI agent identity management as enterprise deployments accelerate, according to new research from Omdia. The study reveals ...
GitHub has confirmed a significant security incident in which threat actor TeamPCP exfiltrated approximately 3,800 internal repositories after compromising an employee's device thr...
Security researcher Justin O'Leary has disclosed a critical vulnerability in Microsoft Azure Backup for Azure Kubernetes Service (AKS) that allowed privilege escalation from a low-...
Braintrust, an AI infrastructure provider, disclosed on March 5 2026 that an unauthorized party had gained access to one of its Amazon Web Services (AWS) accounts. The intrusion, d...
Security researchers have identified a new self‑propagating threat, named PCPJack, that behaves like a worm while simultaneously purging systems infected by the earlier TeamPCP mal...
NVIDIA has officially confirmed a data breach impacting its GeForce NOW service, exposing personal information for a subset of users in Armenia. The disclosure, made in a statement...
Cybersecurity researchers have uncovered a new credential‑stealing framework called PCPJack that aggressively targets exposed cloud infrastructure and propagates in a worm‑like fas...
Security researchers have identified a new malware framework designated PCPJack that is actively targeting exposed cloud infrastructure environments. The threat operates as a crede...
Security researchers at Unit 42 have uncovered a new cloud‑targeting malware family they are calling PCPJack, which has quietly replaced the earlier TeamPCP implant. PCPJack distin...
In the past twelve months, enterprises have rushed to embed AI‑powered writing assistants, workflow automations and productivity plugins into their Google Workspace and Microsoft 3...
Kaspersky researchers identified a surge in phishing campaigns leveraging Amazon Simple Email Service (SES). Attackers abuse the trusted infrastructure by sending emails via verifi...
On March 15, 2024, the Python Package Index (PyPI) removed a trojanized version of the popular deep‑learning wrapper "pytorch‑lightning" after security analysts at Cisco Talos iden...
Amazon Simple Email Service (SES), the cloud‑based email sending platform offered by Amazon Web Services, is increasingly being weaponized by threat actors to distribute phishing e...
Kaseya announced a live webinar titled “Why MSPs must rethink security and backup strategies” scheduled for June 15, 2026 at 2:00 PM ET. The session, hosted by Kaseya’s Product Mar...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-31431, a critical Linux kernel privilege escalation vulnerability, to its Known Exploited Vulner...
Security researchers have flagged a new iteration of the consent‑phishing tool known as ConsentFix, now labeled v3, which dramatically expands the scale and automation of attacks a...
Cybersecurity researchers have identified two distinct cybercrime groups orchestrating rapid, high‑impact extortion campaigns that operate almost entirely within Software‑as‑a‑Serv...
Managed security services are on a steep ascent, with the market expected to swell from $38.31 billion in 2025 to $69.16 billion by 2030, making cybersecurity the fastest‑growing s...
Security researchers at SentinelOne and WithSecure have uncovered a sophisticated Python-based backdoor named DEEP#DOOR that leverages legitimate tunneling services to establish co...
Oracle Red Bull Racing has launched a sweeping automation initiative aimed at embedding security directly into the team’s high‑velocity development pipelines. With the pit wall and...
Security teams across industries are increasingly discovering that traditional vulnerability management approaches fail to accurately represent organizational risk. Despite closing...
In the rush to hybrid cloud adoption, many organizations treat data movement as a simple connectivity chore. Open a ticket, spin up an SFTP gateway, push the data across, and consi...
Silverfort’s identity threat research team disclosed a critical misconfiguration in a Microsoft Entra ID administrative role designed for AI agents. The role, named “AI Service Adm...
Cybersecurity researchers have identified a sophisticated campaign conducted by the threat actor UNC6692, who is combining social engineering, custom malware, and cloud infrastruct...
Glasswing’s recent announcement that it has secured the core code of its platform is a welcome step toward reducing software vulnerabilities, but security experts warn that the bro...
Security researchers at Secureworks’ Counter Threat Unit (CTU) have uncovered a sophisticated espionage operation conducted by a Chinese state‑sponsored APT that targeted Mongolian...
In a live demonstration at the Dark Reading CyberStorm conference, researchers from Sentinel Labs unveiled 'Zealot', a proof‑of‑concept AI framework designed to autonomously compro...
Security researchers at SecureSphere Labs have uncovered a new file‑wiping worm they have named CanisterWorm, attributed to a financially motivated threat actor tracked under the a...
Google has publicly pushed back against viral claims circulating online that all 2.5 billion Gmail accounts have been compromised in a sweeping security incident. The rumors, which...