Love, Bonito Exposed: Singaporean Fashion Retailers Data Breach Puts Customer Information at Risk
Love, Bonito Data Breach Highlights the Growing Risk of Customer Data Exposure in E-CommerceSingapore-based fashion retailer Love, Bonito has disclosed a cybersecurity incident in which a vulnerability on its website po…
Jul 31, 2026
MikroTik RouterOS
CISA Warns of MikroTik RouterOS Weakness That Could Expose WireGuard Private KeysThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory concerning a security w…
Jul 31, 2026
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
The Azure Cosmos DB flaw highlights one of the most serious categories of cloud security risk: a vulnerability in the managed platform itself.Azure Cosmos DB is a widely used Microsoft cloud database service. Organizati…
Jul 31, 2026
Analog Devices discloses data breach, says operations unaffected
The Cisco Secure Firewall Management Center static-credential flaw highlights a serious and uncomfortable reality: security management platforms are now prime targets for attackers.Cisco Secure Firewall Management Cente…
Jul 31, 2026
JetBrains warns of critical TeamCity remote code execution flaw
The critical TeamCity remote code execution flaw highlights why CI/CD platforms must be treated as high-value infrastructure, not just developer tooling.TeamCity is used to build, test, package, release, and deploy soft…
Jul 31, 2026
South Korea fines telco giant KT $39 million for customer data breach
The South Korean fine against KT highlights how telecom data breaches can create serious risks for customers, regulators, and national digital trust.KT is one of South Korea’s major telecommunications providers, which m…
Jul 31, 2026
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)
The SANS ISC diary on an SSH bot performing hardware reconnaissance before deploying a miner highlights an important point: not every malicious login immediately drops malware, but that does not make it harmless.The obs…
Jul 30, 2026
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The critical Ruby on Rails Active Storage vulnerability highlights how a simple image upload feature can become a serious server-side data exposure risk.The flaw, tracked as CVE-2026-66066, affects Rails applications th…
Jul 30, 2026
Cisco warns of FMC static credential flaw exploited in zero-day attacks
The Cisco Secure Firewall Management Center static-credential flaw highlights a serious and uncomfortable reality: security management platforms are now prime targets for attackers.Cisco Secure Firewall Management Cente…
Jul 30, 2026
Sunrise Data Breach: 13GB of Sensitive Data Compromised
The Sunrise Company data breach highlights how ransomware and data theft can affect more than internal IT systems. In real estate and development businesses, the exposed information may include employees, clients, contr…
Jul 30, 2026
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
The three critical VMware vulnerabilities highlight why virtualization infrastructure must be treated as one of the most sensitive layers in the enterprise.VMware environments are not ordinary server platforms. vCenter …
Jul 29, 2026
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
The Ruflo MCP vulnerability highlights a serious new risk in AI infrastructure: tool bridges can become command-execution interfaces if they are exposed without proper authentication.Ruflo is an agent meta-harness used …
Jul 29, 2026