Hackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs.
Hi, what are you looking for?
Hackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs.
Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access.
The privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update.
Hackers accessed the institution’s internal network and deleted two drives containing employee, student, and university data.
Wiz has disclosed the details of a new AI coding assistant attack method it has dubbed GhostApproval.
The security refresh resolves 13 use-after-free bugs, including two critical-severity flaws found by Google.
The Spanish startup has closed an extended pre-seed funding round two months after launching its digital identity protection platform.
Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface.
The professional services giant says it contained the incident, remediated its source, and experienced no operational or service delivery impact.
Cisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors.
Join the webinar as we break down why email-layer defenses alone can’t keep pace with the modern phishing ecosystem.
The "Rogue Agent" vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project.
Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch.
Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication.
The alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data.
Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets.
The audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises.
Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10.
Researchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel.
Tarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typical.