Register to enjoy free access and explore the tools, strategies, and frameworks needed to build a resilient security program for a world where every minute counts.
Hi, what are you looking for?
Register to enjoy free access and explore the tools, strategies, and frameworks needed to build a resilient security program for a world where every minute counts.
DockSec, an OWASP incubator project, correlates findings from multiple container security scanners and uses AI to generate plain-English remediation guidance and exact Dockerfile fixes.
Lithuanian authorities are on high alert after a massive data leak involving more than 600,000 entries from national data registers.
The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors.
Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.
The affected third-party vendor has not been named, but one possible candidate is TriZetto.
Threat actors stole files containing names and protected health information from the healthcare organization’s systems.
Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.
Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets.
Hackers accessed names, addresses, Social Security numbers, financial information, and medical data from third-party partner repositories.
Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.
The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic.
Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites.
Other noteworthy stories that might have slipped under the radar: CISA contractor exposes credentials, Mythos testing and new features, Huawei router flaw triggered telecom blackout.
Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges.
The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions.
CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One.
Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated.
Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges.
The company has developed a platform that uses specialized AI agents to inspect every incoming message.