Attack in the wild · Critical
2026-08-11
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
Source: Krebs on Security →
Attack in the wild · Critical
2026-09-09
"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
Source: Dark Reading →
Vulnerability · Critical
2026-09-03
The recent open letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.
Source: Dark Reading →
Attack in the wild · Critical
2026-09-02
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
Source: Dark Reading →
Attack in the wild · Critical
2026-09-01
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
Source: Dark Reading →
Attack in the wild · Critical
2026-09-01
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
Source: Dark Reading →
Attack in the wild · Critical
2026-08-31
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
Source: Dark Reading →
Attack in the wild · Critical
2026-08-25
Attackers can exploit a security bug in Nvidia's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.
Source: Dark Reading →
Vulnerability
2026-09-08
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security expe
Source: Krebs on Security →
Vulnerability
2026-09-01
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appea
Source: Krebs on Security →
Attack in the wild
2026-08-27
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (
Source: Krebs on Security →
Vulnerability
2026-08-14
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away i
Source: Krebs on Security →
Vulnerability
2026-08-06
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka,
Source: Krebs on Security →
Vulnerability
2026-07-30
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds
Source: Krebs on Security →
Vulnerability
2026-07-22
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and oth
Source: Krebs on Security →
Vulnerability
2026-07-14
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attribu
Source: Krebs on Security →
Vulnerability
2026-07-13
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by Kr
Source: Krebs on Security →
Vulnerability
2026-09-10
Starting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.
Source: Dark Reading →
Vulnerability
2026-09-09
An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.
Source: Dark Reading →
Vulnerability
2026-09-09
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.
Source: Dark Reading →