Stay informed about the latest cybersecurity threats, vulnerabilities, malware campaigns, phishing trends, supply-chain attacks, and security advisories. This section provides timely updates and practical insights to help organizations understand emerging risks and strengthen their security posture.
Trezor’s disclosure that another 67,000 U.S. customers were affected by the ShipMonk breach significantly changes the understanding of the incident. The newly identified records relate to orders…
Broadcom has released fixes for two serious vulnerabilities in VMware Workstation and VMware Fusion, including a critical flaw that can allow an attacker with administrative privileges inside a virtua…
The breach of JetBrains Cadence is a particularly important incident because it combines several high-risk elements in one attack: an internet-facing CI/CD component, a critical unauthenticated remote…
The discovery of a new zero-day vulnerability affecting Magento Open Source and Adobe Commerce is particularly serious because attackers are already exploiting the flaw while no official Adobe patch i…
CISA’s addition of CVE-2026-85046 to the Known Exploited Vulnerabilities Catalog on September 4, 2026 materially changes how organizations should prioritize the recently disclosed Chrome vulnera…
Google has released an emergency Chrome security update addressing CVE-2026-85046, a high-severity type-confusion vulnerability in the V8 JavaScript and WebAssembly engine that Google says is already …
The targeting of CVE-2026-19490 against Citrix NetScaler ADC and NetScaler Gateway appliances is particularly concerning because the vulnerable systems often sit directly on the enterprise perimeter a…
Reports linking IDScan.net to a dark-web marketplace offering access to more than 153 million U.S. and Canadian driver’s-license records highlight one of the most uncomfortable contradictions in…
CISA’s ICSA-26-246-02 advisory covers a critical vulnerability in the IXON VPN Client that could allow an attacker to execute commands with root or SYSTEM privileges on the computer running the …
The growing abuse of Node.js in targeted attacks is another example of how threat actors increasingly prefer to operate through trusted software rather than introduce obviously malicious binaries. Acc…
CISA’s ICSA-26-246-07 advisory highlights a critical vulnerability in Pyramid Solutions’ NetStaX EtherNet/IP Stack that deserves particular attention because the weakness exists in a reusa…
The disclosure that an unauthorized party obtained files from Thomson Reuters’ C-Track court case-management environment highlights the unusually sensitive risks created when judicial systems de…
The discovery of BraZetsu, a Python-based Windows malware framework linked by Group-IB to an operation tracked as Exilware, highlights an important evolution in the initial-access-broker economy. Inst…
Cisco has disclosed a critical vulnerability in certain Silicon One-based Nexus 9000 Series switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.…
The compromise of Coder’s registry infrastructure is a strong reminder that software supply-chain attacks do not always require compromising source-code repositories or poisoning a package at th…
The €500,000 fine imposed by France's data protection authority, CNIL, on Hôpital privé de la Loire provides an important reminder that a data breach is not automatically what …
Plex has urged users to update both Plex Media Server and Plex Desktop immediately after releasing fixes for multiple security vulnerabilities. The affected server versions include Plex Media Server 1…
The public release of FalconFlank, a proof-of-concept claiming to demonstrate local privilege escalation through CrowdStrike Falcon Sensor, raises an important issue for endpoint security architecture…
An active malware campaign using fake software download websites to impersonate well-known vendors demonstrates how effective social engineering remains when attackers combine it with trusted Windows …
A high-severity vulnerability in the widely used All-in-One WP Migration and Backup plugin demonstrates how software intended to protect and recover websites can itself become a path to complete compr…