CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.
Hi, what are you looking for?
CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.
The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector.
The US has seized several domains used by Handala in cyber-enabled psychological operations.
The lesser-known JackSkid and Mossad botnets have also been targeted in the operation.
It was previously estimated that more than 1.6 million people may be affected by the Marquis data breach.
The SharePoint remote code execution vulnerability CVE-2026-20963, which Microsoft patched in January, has been exploited in the wild.
Amazon found evidence that the FMC software vulnerability has been exploited since late January, and found links to Russia.
The medtech giant has been working on restoring systems affected by the cyberattack conducted by the Handala hackers.
Meta does not plan on fixing the vulnerability because it involves the use of a modified client application.
The government agency confirmed the vulnerability could have been exploited to obtain company details and alter records.
Several major tech and retail companies have signed an industry accord against online scams and fraud.
Broadcom, Bechtel, Estée Lauder, and Abbott Technologies are the only major companies that have yet to issue a public statement.
Initial evidence indicates Iran may be behind the attack, but officials admitted it could be a false flag.
Personal information such as names, email addresses, and phone numbers was accessed by hackers.
Starbucks said the incident involved phishing attacks targeting an employee portal, affecting hundreds.
Evidence indicates that the attackers leveraged existing endpoint management software rather than malware to wipe devices.
Law enforcement agencies in the US and Europe targeted the cybercrime service that has impacted 360,000 devices since 2020.
The company has released iOS and iPadOS versions 16.7.15 and 15.8.7 to patch the vulnerabilities.
The social media giant has disabled more than 150,000 accounts powering scam centers in Asia.
The 2024 incident was initially linked to China, but an infostealer infection has now revealed North Korean involvement.