Incident response firm Sygnia has detailed a sophisticated espionage campaign in which a China-linked group implanted malware directly inside Cisco routers and authentication servers to intercept credentials and erase evidence of its own presence.
PaperCut has rushed out two rounds of emergency patches after researchers found attackers chaining two zero-day vulnerabilities to gain remote code execution on unpatched NG and MF print servers, with active exploitation confirmed since August 26.
A critical bug in Keycloak's password reset flow, tracked as CVE-2026-18963 with a CVSS score of 9.1, could have let attackers take over any account without ever accessing the victim's email.
A four-year study by Truffle Security found more than 9,300 exposed AWS access keys remain active today, including hundreds of root and administrator-level credentials capable of handing an outsider full control of a company's cloud account.
DNS4EU is a European Union initiative aimed at strengthening digital sovereignty and cybersecurity. Unlike foreign DNS services that often lack GDPR compliance and transparency,...
For years, vulnerability management has been reduced to a simple equation:
CVSS ≥ 9 = Drop everything and patch.
The problem is that attackers don't think...
Google has released an emergency Chrome update to fix a zero-day vulnerability in the browser's V8 engine that attackers are already exploiting in the wild. Users should update immediately.
CISA added seven actively exploited vulnerabilities, including two rated maximum severity, to its Known Exploited Vulnerabilities catalog, with attackers already using them to deploy reverse shells and cryptocurrency miners.
Nearly 22,000 Microsoft Exchange servers worldwide remain unpatched against a high-severity authentication bypass flaw with public exploit code, weeks after Microsoft released a fix.
Attackers are actively exploiting a critical authentication bypass in JFrog Artifactory that lets them create their own admin accounts, according to researchers at watchTowr. Self-hosted customers who have not yet patched should update immediately.
PaperCut has rushed out two rounds of emergency patches after researchers found attackers chaining two zero-day vulnerabilities to gain remote code execution on unpatched NG and MF print servers, with active exploitation confirmed since August 26.
A dark web marketplace called Nexus is selling scans of more than 153 million US and Canadian driver's licenses that researcher Brian Krebs traced to identity verification firm IDScan.net, whose clients include Hertz, Target and FedEx. The FBI has opened an investigation and class action lawsuits have followed.