The company detected a network intrusion in March and an investigation showed that some files were stolen during the attack.
Hi, what are you looking for?
The company detected a network intrusion in March and an investigation showed that some files were stolen during the attack.
The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet.
As AI agents, machine identities, and third-party applications multiply across enterprises, Offroad is betting autonomous security agents can restore control over an increasingly unmanageable identity landscape.
Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.
Willow (formerly Webrix) emerged from stealth mode with an access platform designed to secure enterprise AI agents.
Attackers could have triggered dangerous actions, including controlling smart home devices via Google Home and starting Zoom video calls.
A flaw in the Full Page Cache Warmer extension can be exploited without authentication via serialized PHP object payloads.
Relying on social engineering, the hacking group engages in credential phishing, malware distribution, and fraud activities.
Law enforcement and tech companies disrupted infrastructure linked to scammers operating across Southeast Asia.
The high-severity flaw can be exploited remotely, without authentication, in server-side request forgery (SSRF) attacks.
A researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance.
Coralogix offers a full-stack observability platform that unifies logs, metrics, traces, security, and AI observability.
Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.
The AI Risk Quadrant evaluates AI agents based on three factors: how vulnerable they are to compromise, the potential impact of a breach, and the strength of their security defenses.
The attackers had access to a senior executive’s email account for 150 days and exfiltrated data for months.
The affected individuals’ personal information was stolen from a legacy server managed by a third party.
An improper authentication bug allows attackers to escalate their privileges and escape containers.
The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold.
Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.
The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release.