Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
A CVSS 10.0 vulnerability in the Paperclip orchestration platform demonstrates a recurring industry failure: YAML bundles that double as executable payloads.
Kaspersky's GReAT team reports 75 million attacks blocked in APAC during the first half of 2026, alongside warnings over rising global supply chain threats.
CrowdStrike's latest Threat Hunting Report traces a multiyear shift from conventional intrusions toward attacks that exploit trusted identities, cloud services, AI systems, and software dependencies.
Zoom has patched a vulnerability that could allow attackers to execute code on other meeting participants’ systems.
Tenet Security showed how a publicly exposed error-tracking credential and an MCP integration chain into remote code ...
Microsoft reveals hackers are exploiting BNB Chain smart contracts and fraudulent CAPTCHA verification pages to distribute malware targeting passwords and wallets.
A massive supply chain attack on the Node Package Manager (npm) registry has infected over 400 packages with over 2 billion downloads with the ...
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without ...
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under ...
QuickFox VPN users might be at risk. Researchers discovered that attackers trojanized the software's Windows installer for ...