FortiSandbox Vulnerabilities Expose Systems to Auth Bypass and Command...
FortiSandbox Vulnerabilities Expose Systems to Auth Bypass and Command Execution Fortinet FortiSandbox administrators should review their environments after several critical vulnerabilities raised con...
May 2026: TeamPCP's Supply Chain Blitz Hits Checkmarx, GitHub, and npm
May 2026: TeamPCP’s Supply Chain Blitz Hits Checkmarx, GitHub, and npm May 2026 was defined by two threat actors operating at full intensity in parallel. ShinyHunters executed a major education-sector...
FortiBleed: The Compromise of 30,000 Fortinet Firewalls
FortiBleed: The Compromise of 30,000 Fortinet Firewalls Fortinet firewalls and VPN gateways are among the most widely deployed network security devices in the world. Organizations across every sector ...
Top 5 Phishing Domain Takedown Service
Top 5 Phishing Domain Takedown Service Phishing attacks remain one of the most persistent and scalable threats facing organizations today. In Q1 2026 alone, approximately 8.3 billion email-based phish...
CVE-2026-20262: Cisco Catalyst SD-WAN Manager Zero-Day Leads to Root
CVE-2026-20262: Cisco Catalyst SD-WAN Manager Zero-Day Leads to Root CVE-2026-20262 is a zero-day vulnerability in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that lets an authenticated at...
The Quarry: Inside the PhaaS Operation Behind Hundreds of IRS and SSA ...
The Quarry: Inside the PhaaS Operation Behind Hundreds of IRS and SSA Phishing Campaigns What looks like a wave of disconnected phishing incidents – some impersonating the IRS, others mimicking the So...
Dark Web Profile: Fox Kitten
Dark Web Profile: Fox Kitten Fox Kitten stands out among Iranian Advanced Persistent Threat (APT) groups for operating on two tracks simultaneously: collecting intelligence for the Iranian regime whil...
Iran Hajj Organization Data Claim, Crypto Leads Sale, APT43 Tooling Cl...
Iran Hajj Organization Data Claim, Crypto Leads Sale, APT43 Tooling Claim, Sweden User Data, and Chrysler Breach Claim SOCRadar’s Dark Web Team identified several new underground posts, including an a...
What the EU AI Act Actually Requires for Cybersecurity (And Where Ente...
What the EU AI Act Actually Requires for Cybersecurity (And Where Enterprises Are Exposed) The EU AI Act contains specific cybersecurity requirements. Article 15 names the threats. Article 73 sets rep...
Dark Web Profile: Rock
Dark Web Profile: Rock Most Phishing-as-a-Service operations are run by a faceless brand. Rock is the opposite: a single developer who builds, maintains, and sells an entire phishing and remote access...
CVE-2026-35273 in Oracle PeopleSoft PeopleTools EMHub Under Active Exp...
CVE-2026-35273 in Oracle PeopleSoft PeopleTools EMHub Under Active Exploitation Oracle has disclosed CVE-2026-35273, a critical Remote Code Execution (RCE) zero-day vulnerability in Oracle PeopleSoft ...
New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phi...
New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phishing Kits Pink Data Extortion Group is emerging as one of the latest examples of how voice phishing and data extortion continue t...
Electronic Warfare, Drones, and Cyber: Inside Modern Hybrid Warfare
Electronic Warfare, Drones, and Cyber: Inside Modern Hybrid Warfare Electronic warfare, drone warfare, and cyber operations all depend on the same foundation, the electromagnetic spectrum and the digi...
Dark Web Profile: Tengu Ransomware (Shisa)
Dark Web Profile: Tengu Ransomware (Shisa) Despite a measured public persona, Tengu Ransomware operates as a financially motivated, well-organized threat. First observed in late 2025, the group emerge...
ServiceNow Breach: Customer Data Exposed Through Unauthenticated API A...
ServiceNow Breach: Customer Data Exposed Through Unauthenticated API Access In early June 2026, ServiceNow notified impacted customers about malicious activity involving unauthorized access to custome...
Ivanti Sentry’s CVE-2026-10520 Enables Root RCE
Ivanti Sentry’s CVE-2026-10520 Enables Root RCE CVE-2026-10520 is a critical OS command injection vulnerability in Ivanti Sentry that can allow a remote, unauthenticated attacker to execute commands a...
June 2026 Patch Tuesday: 206 Vulnerabilities, Three Zero-Days Includin...
June 2026 Patch Tuesday: 206 Vulnerabilities, Three Zero-Days Including HTTP/2 Bomb Flaw (CVE-2026-49160) Microsoft released its June 2026 Patch Tuesday security updates, resolving a total of 206 vuln...
SAP Security Patch Day June 2026: Critical CVE-2026-44748 SAML Flaw Co...
SAP Security Patch Day June 2026: Critical CVE-2026-44748 SAML Flaw Could Allow Full Authentication Bypass On June 9, 2026, SAP released its monthly security updates, which included 15 new Security No...
What Do You Need to Know About Claude Fable 5?
What Do You Need to Know About Claude Fable 5? On June 9, 2026, Anthropic released Claude Fable 5, calling it the most capable model it has ever made available to the general public. For security team...
CVE-2026-11645: Exploited Chrome V8 Bug Enables In-Browser Code Execut...
CVE-2026-11645: Exploited Chrome V8 Bug Enables In-Browser Code Execution CVE-2026-11645 is a high-severity Google Chrome zero-day in the V8 JavaScript/WebAssembly engine caused by an out-of-bounds (O...