Threat actors gained access to personal and protected health information that Xsolis received from its clients.
Hi, what are you looking for?
Threat actors gained access to personal and protected health information that Xsolis received from its clients.
Squidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability.
Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data.
A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.
Groups like ShinyHunters are demonstrating that attackers do not necessarily need malware or zero-day exploits to cause massive damage.
The vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers.
A database of over 86,000 confirmed working credentials was created during the credential-harvesting campaign.
HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers.
Hackers stole personal information after breaching the systems of a third-party license vendor serving TPWD.
French President Emmanuel Macron urged the world’s wealthy democracies to work together on regulating advanced AI systems.
Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover.
CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution.
The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs.
The hackers exfiltrated data from Salesforce instances of Klue customers, such as Huntress and Recorded Future.
WideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius.
Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.
CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution.
These servers are regularly targeted by China-linked UNC6508 for initial access and backdoor deployment.
The deal values industrial cybersecurity giant Dragos at $3.25 billion, and runZero and NetRise will operate under Dragos.
Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.