The active exploitation of vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress is particularly serious because t…
Aug 25, 2026
The disclosure of CVE-2026-75501 in the Calix GS7 XGS GS5239XG residential gateway is particularly serious because it breaks one of the mos…
Aug 25, 2026
The ReliaQuest incident is a useful example of why modern identity attacks cannot be judged simply by whether an attacker obtained a userna…
Aug 24, 2026
The breach involving South Korea’s government-backed startup platform Modu-ui Changup is a particularly good example of why encryption alon…
Aug 24, 2026
The disclosure of CVE-2026-18963 in Keycloak deserves immediate attention because it affects one of the most sensitive workflows in any ide…
Aug 24, 2026
The cyberattack on Latvia’s Road Traffic Safety Directorate, CSDD, is particularly significant because the attackers did not merely obtain …
Aug 24, 2026
CISA’s August 21, 2026 addition of CVE-2026-73570 to the Known Exploited Vulnerabilities catalog materially increases the urgency around th…
Aug 24, 2026
The Oz Hair and Beauty data breach is another useful reminder that the absence of stolen payment-card details does not make a customer-data…
Aug 24, 2026
The SickKids cybersecurity incident is a useful reminder that an organisation’s security posture increasingly depends on software it does n…
Aug 22, 2026
The discovery of more than 9,300 still-valid AWS access keys exposed publicly over the past four years is a striking reminder that cloud co…
Aug 22, 2026
The SynkLoader campaign is an important example of how phishing is moving beyond email and into collaboration platforms that employees natu…
Aug 22, 2026