460 articles
Apache HTTP Server CVE-2026-23918 (CVSS 8.8) enables DoS and potential RCE via double-free in HTTP/2 handling. Affects all mod_http2 users. Patch now.
Cisco Talos: CloudZ RAT's new Pheno plugin abuses Windows Phone Link to read SMS and OTPs from local SQLite database.
Cyera discloses CVE-2026-7482 (CVSS 9.3) — a heap out-of-bounds read in Ollama's GGUF model loader that leaks prompts, API keys, and secrets via three unauthenticated API calls.
HeroDevs analysis: 5.4M EOL package versions across npm, PyPI, Maven evade SCA scanners; ~80% of CVEs on supported versions also affect unlisted EOL releases. Free scan offered.
OAuth tokens with no expiration persist in Google and Microsoft tenants — attackers bypass MFA and perimeter controls.
ShinyHunters leaked a 106GB archive of Vimeo data after breaching Anodot, exposing emails and names of 119,200 users. No credentials or payment info compromised.
A 23-year-old student used SDR gear to clone TETRA radio parameters, sending a 'General Alarm' signal that halted 4 THSR trains for 48 minutes.
Attackers stole source code from Trellix, exposing detection logic and control locations in its security products. The breach amplifies supply chain risks for enterprise customers.
Cisco announced plans to acquire Astrix Security to address non-human identity risks in AI and machine workloads. The deal expands Cisco's identity security portfolio.
Malwarebytes Lock and Code podcast: Eva Velasquez details how small business cyberattacks create a 'cyber tax' that raises prices for all consumers — no sector immune.
SecurityWeek reports 33 cybersecurity M&A deals in April 2026, including acquisitions by Airbus, Cyera, Fortra, Palo Alto Networks, Silverfort, and Socket.
Infrastructure confirmed hackers accessed Canvas user data — names, emails, student IDs, messages — from educational institutions.