Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.
Hi, what are you looking for?
Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.
Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets.
Hackers accessed names, addresses, Social Security numbers, financial information, and medical data from third-party partner repositories.
Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.
The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic.
Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites.
Other noteworthy stories that might have slipped under the radar: CISA contractor exposes credentials, Mythos testing and new features, Huawei router flaw triggered telecom blackout.
Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges.
The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions.
CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One.
Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated.
Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges.
The company has developed a platform that uses specialized AI agents to inspect every incoming message.
The company blocked over 1.1 billion accounts and $2.2 billion in potentially fraudulent transactions.
CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution.
The company will invest in its firewall, certified patches, protection extensions, new products, and team expansion.
The bugs could be exploited to elevate privileges to System or create a denial-of-service (DoS) condition.
More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’.
New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking.
The new Series A funding round brings the total raised by Quantum Bridge to $16 million.