CVE-2026-34486: Apache Tomcat Tribes Regression Creates Unauthenticate...
CVE-2026-34486: Apache Tomcat Tribes Regression Creates Unauthenticated RCE Path Apache Tomcat users running Tribes clustering should pay attention to CVE-2026-34486, an important-severity regression ...
Claude Code & ChatGPT Used to Steal Millions of Records in Mexican Gov...
Claude Code & ChatGPT Used to Steal Millions of Records in Mexican Government Breach A cyberattack spanning nine Mexican government organizations has become one of the clearest examples yet of how...
Alleged Police Tipline Data Sale, iOS and Adobe Exploits, RDWeb Access...
Alleged Police Tipline Data Sale, iOS and Adobe Exploits, RDWeb Access Listings, and Gunra Recruitment SOCRadar’s Dark Web Team identified several new underground posts this week, including an alleged...
CVE-2026-34621: Adobe Acrobat Reader Zero-Day Enables Arbitrary Code E...
CVE-2026-34621: Adobe Acrobat Reader Zero-Day Enables Arbitrary Code Execution via Crafted PDF Adobe released an emergency update for Adobe Acrobat and Adobe Acrobat Reader on Windows and macOS to add...
Could XChat Become a Telegram Rival and a Future Hub for Threat Actors...
Could XChat Become a Telegram Rival and a Future Hub for Threat Actors? X’s upcoming messaging app, XChat, is being presented as more than a simple upgrade to direct messages. Public details point to ...
How Phishing Kits Targeting U.S. Giants Are Built, Sold, and Deployed
How Phishing Kits Targeting U.S. Giants Are Built, Sold, and Deployed Modern phishing kits can steal authenticated sessions from Microsoft 365 and Google accounts in real time, even when MFA is enable...
Dark Web Profile: TeamPCP
Dark Web Profile: TeamPCP TeamPCP is a financially motivated cybercriminal group that executed the most consequential open-source supply chain attack campaign of 2026, compromising security tools trus...
Claude Mythos Preview Signals a New Phase for AI in Vulnerability Rese...
Claude Mythos Preview Signals a New Phase for AI in Vulnerability Research Anthropic’s Claude Mythos Preview is drawing attention because it showed a much stronger ability to find and exploit software...
FBI IC3 2025 Internet Crime Report: 10 Important Takeaways
FBI IC3 2025 Internet Crime Report: 10 Important Takeaways The FBI’s Internet Crime Complaint Center (IC3) has just released its 2025 Annual Report, and it’s a record-breaker in the worst way. For the...
The Unknown Stealers: What's Hidden Below the Radar
The Unknown Stealers: What’s Hidden Below the Radar The stealer ecosystem has matured into a professionalized criminal economy that most organizations are simply not monitoring closely enough. While t...
BlueHammer Windows Zero-Day: Privilege Escalation Risk
BlueHammer Windows Zero-Day: Privilege Escalation Risk A newly exposed Windows zero-day known as BlueHammer has become a serious concern because it can let an attacker move from a limited user account...
Alleged TrakCare Access, PowerLab Leak, U.S. Driver IDs, Hong Kong HA ...
Alleged TrakCare Access, PowerLab Leak, U.S. Driver IDs, Hong Kong HA Data and More SOCRadar’s Dark Web Team identified several new underground posts this week, including an alleged unauthorized acces...
Pro-Iran Cyberattacks on Financial Services: 144 Incidents
Pro-Iran Cyberattacks on Financial Services: 144 Incidents Financial services is the #2 most targeted sector in the entire campaign, and for reasons that are deliberate, documented, and rooted in more...
CVE-2026-35616: FortiClient EMS API Auth Bypass Enables Command Execut...
CVE-2026-35616: FortiClient EMS API Auth Bypass Enables Command Execution Fortinet disclosed a critical vulnerability in Fortinet FortiClient EMS (Enterprise Management Server) tracked as CVE-2026-356...
Progress ShareFile Flaws CVE-2026-2699 & CVE-2026-2701 RCE
Progress ShareFile Flaws CVE-2026-2699 & CVE-2026-2701 RCE A newly disclosed Progress ShareFile pre-auth RCE chain is drawing attention after researchers showed how CVE-2026-2699 and CVE-2026-2701...
CVE-2026-20093: Critical Cisco IMC Flaw Allows Unauthenticated Admin A...
CVE-2026-20093: Critical Cisco IMC Flaw Allows Unauthenticated Admin Access to UCS Servers CVE-2026-20093, is an authentication bypass flaw found in the change password functionality of Cisco Integrat...
CVE-2026-5281: Chrome WebGPU Zero-Day Exploited In The Wild
CVE-2026-5281: Chrome WebGPU Zero-Day Exploited In The Wild Google patched CVE-2026-5281, a high-severity use-after-free (CWE-416) vulnerability in Dawn, Chromium’s WebGPU implementation. The company ...
BLACKNET-00: The Ransomware-as-a-Service Platform That Weaponizes Medi...
BLACKNET-00: The Ransomware-as-a-Service Platform That Weaponizes Mediocrity How a Custom Ransomware Builder Collapses the Technical Barrier Between Script Kiddies and Enterprise-Grade Ransomware Oper...
Trivy-Linked Cisco Breach & ShinyHunters’ Stolen Data Claim
Trivy-Linked Cisco Breach & ShinyHunters’ Stolen Data Claim Cisco is facing fresh scrutiny after a breach of its internal development environment was linked to the Trivy supply chain compromise. A...
CVE-2025-53521: F5 BIG-IP APM Flaw Reclassified as Unauthenticated RCE
CVE-2025-53521: F5 BIG-IP APM Flaw Reclassified as Unauthenticated RCE CVE-2025-53521 is a vulnerability in F5 BIG-IP Access Policy Manager (APM) that was initially treated as a denial-of-service cond...