Vulnerabilities Recent macOS Screen Sharing Vulnerability Exploited in Attacks Threat actors gained root access to the vulnerable systems and deployed a Monero miner. Ionut Arghire14 hours ago
Vulnerabilities Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. Eduard Kovacs14 hours ago
Supply Chain Security Trivy, Not LiteLLM Behind the 2,500 Org Compromise Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. Ionut Arghire3 days ago
Data Breaches 1.6 Million Likely Impacted by RingCentral Data Breach The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers. Ionut Arghire4 days ago
Vulnerabilities Hackers Exploiting Unpatched GeoServer Zero-Day The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. Ionut Arghire4 days ago
Vulnerabilities Adobe Commerce Bug Targeted Immediately After Disclosure The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. Ionut Arghire4 days ago
Government White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. Eduard Kovacs5 days ago
Malware & Threats Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. Kevin Townsend5 days ago
Cybercrime Ceva Logistics Operations Disrupted by Cyberattack Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers. Ionut Arghire5 days ago
Supply Chain Security Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. Ionut Arghire6 days ago
Vulnerabilities Cisco Patches Firewall Zero-Day Exploited for DoS Attacks CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. Eduard Kovacs6 days ago
Vulnerabilities August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. Ionut Arghire6 days ago
Vulnerabilities Zoom Patches Zero-Click Code Execution Vulnerability Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. Ionut Arghire6 days ago
Artificial Intelligence OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI. Eduard Kovacs7 days ago
Application Security Mozilla Issues New Firefox GPG Key Following Exposure The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. Eduard Kovacs7 days ago
Artificial Intelligence OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. Eduard KovacsAugust 10, 2026
ICS/OT Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. Eduard KovacsAugust 10, 2026
Vulnerabilities Critical Flaws Discovered in Belgian eID Software Used by 2 Million People The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. Eduard KovacsAugust 10, 2026
Artificial Intelligence Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. Eduard KovacsAugust 8, 2026
ICS/OT Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. Eduard KovacsAugust 7, 2026