CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog.
Hi, what are you looking for?
CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog.
Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala.
The exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project.
CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching.
Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.
A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities.
Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release.
Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June.
Named EmberAI, the new capability is built on Dragos’ massive operational technology cybersecurity dataset.
26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy.
Federal agencies are required to transition high-value assets and high-impact systems to use PQC by the end of 2030 and 2031.
Threat actors gained access to personal and protected health information that Xsolis received from its clients.
Squidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability.
The vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers.
Hackers stole personal information after breaching the systems of a third-party license vendor serving TPWD.
WideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius.
CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution.
The deal values industrial cybersecurity giant Dragos at $3.25 billion, and runZero and NetRise will operate under Dragos.
The Android malware allows its operators to take control of infected devices and harvest sensitive information.
Israel-based Entro specializes in non-human identity and credential security solutions, and it will enable SailPoint to enhance its products.