Breaches, vulnerabilities, and the defenses that matter.
+follow topic ← all stories
Security 7-Zip fixes remote code execution flaw in version 26.02 The popular file compression tool's vulnerability affects millions of users who could execute malicious code simply by opening a crafted archive.
Security WordPress Core wp2shell RCE Vulnerabilities Now Have Public Exploits Over 40% of all websites run on WordPress, and public exploits dramatically shorten the window for attackers to compromise unpatched installations.
Security Microsoft warns of ACR Stealer malware surge targeting enterprise credentials Enterprise browsers store authentication tokens and passwords; a surge in targeted credential theft affects organizational security posture.
Security TP-Link Kasa Cameras Leaked Home GPS via Unauthenticated UDP for Six Years A long-standing vulnerability in widely deployed home cameras exposed precise location data without authentication.
Security Abbott Laboratories Investigates Two Separate Cyber Incidents Healthcare companies hold sensitive patient data, and simultaneous incidents at a major diagnostics provider raise questions about system isolation and response protocols.
Security AI Spam Filters Defeated by Decades-Old Text Salting New AI-powered defenses can be vulnerable to old, low-tech evasion tactics.
Security OpenSSL Vulnerability Allows DDoS with 11-Byte Payload A minimal attack surface can cause outsized infrastructure disruption.
Security Florida Man Arrested for Crypto Theft Through Steam Game Malware Shows how malware delivery has expanded beyond traditional vectors into gaming platforms trusted by millions.
Security Ernst & Young Reports Breach Through Third-Party Support System Third-party support platforms remain a persistent weak point in enterprise security architectures.
Security Capital One Open-Sources VulnHunter AI Security Tool A major bank is sharing an AI agent that scans code for vulnerabilities, signaling wider adoption of agentic security tools in enterprise environments.
Security Windows Zero-Day Grants Admin Access Through Registry Flaw A publicly disclosed exploit targeting up-to-date Windows systems allows privilege escalation, increasing urgency for patch deployment.
Security Android Lock Screen Flaw Lets Gemini Send Messages Without PIN A gesture-based bypass in Android's lock screen allows unauthorized message sending through the Gemini assistant, undermining a core security boundary.
Security FortiSandbox Flaw Added to Federal Exploit Catalog A command-injection flaw in security software reaches the federal urgency list, signaling active exploitation in the wild.
Security Ransomware Attack Halts Coca-Cola's Fairlife Dairy Production A ransomware incident has stopped production across a major US dairy operation, affecting supply chains.
Security Russia's Elite Hackers Adopt ClickFix Social Engineering A technique once used only by cybercriminals for financial gain is now part of nation-state operations.
Security FBI Seizes NetNut Proxy Service in Botnet Crackdown Law enforcement targets infrastructure used to disguise malicious traffic as legitimate residential connections.
Security FBI Warns of Follow-On Extortion After ShinyHunters Campaign An FBI alert confirmed that containing an incident does not mean it is over, as extortion groups continue targeting victims after initial breaches.
Security CISA Contractor Exposes Federal Cloud Credentials in Public Repository The agency tasked with defending federal networks had to improvise its own incident response after a contractor exposed sensitive government system access.
Security Foxconn Confirms Ransomware Attack on North American Factories The attack exposed how a single supplier breach can create cascading risk across the global technology supply chain.
Security Instructure Breach Becomes Largest Education-Sector Incident on Record The breach of Canvas, used by 41% of North American higher education institutions, exposed the risks centralized education platforms pose during critical periods like final exams.