CVE-2026-34621: Adobe Acrobat Reader Zero-Day Enables Arbitrary Code E...
CVE-2026-34621: Adobe Acrobat Reader Zero-Day Enables Arbitrary Code Execution via Crafted PDF Adobe released an emergency update for Adobe Acrobat and Adobe Acrobat Reader on Windows and macOS to add...
Could XChat Become a Telegram Rival and a Future Hub for Threat Actors...
Could XChat Become a Telegram Rival and a Future Hub for Threat Actors? X’s upcoming messaging app, XChat, is being presented as more than a simple upgrade to direct messages. Public details point to ...
Claude Mythos Preview Signals a New Phase for AI in Vulnerability Rese...
Claude Mythos Preview Signals a New Phase for AI in Vulnerability Research Anthropic’s Claude Mythos Preview is drawing attention because it showed a much stronger ability to find and exploit software...
FBI IC3 2025 Internet Crime Report: 10 Important Takeaways
FBI IC3 2025 Internet Crime Report: 10 Important Takeaways The FBI’s Internet Crime Complaint Center (IC3) has just released its 2025 Annual Report, and it’s a record-breaker in the worst way. For the...
BlueHammer Windows Zero-Day: Privilege Escalation Risk
BlueHammer Windows Zero-Day: Privilege Escalation Risk A newly exposed Windows zero-day known as BlueHammer has become a serious concern because it can let an attacker move from a limited user account...
CVE-2026-35616: FortiClient EMS API Auth Bypass Enables Command Execut...
CVE-2026-35616: FortiClient EMS API Auth Bypass Enables Command Execution Fortinet disclosed a critical vulnerability in Fortinet FortiClient EMS (Enterprise Management Server) tracked as CVE-2026-356...
Progress ShareFile Flaws CVE-2026-2699 & CVE-2026-2701 RCE
Progress ShareFile Flaws CVE-2026-2699 & CVE-2026-2701 RCE A newly disclosed Progress ShareFile pre-auth RCE chain is drawing attention after researchers showed how CVE-2026-2699 and CVE-2026-2701...
CVE-2026-20093: Critical Cisco IMC Flaw Allows Unauthenticated Admin A...
CVE-2026-20093: Critical Cisco IMC Flaw Allows Unauthenticated Admin Access to UCS Servers CVE-2026-20093, is an authentication bypass flaw found in the change password functionality of Cisco Integrat...
CVE-2026-5281: Chrome WebGPU Zero-Day Exploited In The Wild
CVE-2026-5281: Chrome WebGPU Zero-Day Exploited In The Wild Google patched CVE-2026-5281, a high-severity use-after-free (CWE-416) vulnerability in Dawn, Chromium’s WebGPU implementation. The company ...
Trivy-Linked Cisco Breach & ShinyHunters’ Stolen Data Claim
Trivy-Linked Cisco Breach & ShinyHunters’ Stolen Data Claim Cisco is facing fresh scrutiny after a breach of its internal development environment was linked to the Trivy supply chain compromise. A...
CVE-2025-53521: F5 BIG-IP APM Flaw Reclassified as Unauthenticated RCE
CVE-2025-53521: F5 BIG-IP APM Flaw Reclassified as Unauthenticated RCE CVE-2025-53521 is a vulnerability in F5 BIG-IP Access Policy Manager (APM) that was initially treated as a denial-of-service cond...
February 2026: ShinyHunters Attacks Hit Odido, CarGurus, Panera Bread,...
February 2026: ShinyHunters Attacks Hit Odido, CarGurus, Panera Bread, and Figure February 2026 brought a fresh wave of data breach disclosures, and the pattern was hard to miss. Extortion-driven atta...
Claude Code Leak: What You Need to Know
Claude Code Leak: What You Need to Know [Update] April 1, 2026: “Has Anthropic Confirmed the Cause of the Claude Code Exposure?”, “Claude Code Leak Sparks Typosquatting Attempts” On March 31, 2026, co...
Axios npm Hijack 2026: Everything You Need to Know – IOCs, Impact & Re...
Axios npm Hijack 2026: Everything You Need to Know – IOCs, Impact & Remediation On March 31, 2026, a threat actor hijacked the npm account of the lead Axios maintainer and published two malicious ...
ShadowPrompt: Zero-Click Prompt Injection Chain in Anthropic’s Claude ...
ShadowPrompt: Zero-Click Prompt Injection Chain in Anthropic’s Claude Chrome Extension A vulnerability chain nicknamed ShadowPrompt affected Anthropic’s official Claude Google Chrome extension. Simply...
TeamPCP's Checkmarx GitHub Actions Attack: What You Need to Know
TeamPCP’s Checkmarx GitHub Actions Attack: What You Need to Know A supply chain incident becomes far more dangerous when it stops looking like a single breach and starts behaving like a multiplier. Th...
CVE-2026-3055: NetScaler Memory Disclosure Puts SAML-Enabled Edge Devi...
CVE-2026-3055: NetScaler Memory Disclosure Puts SAML-Enabled Edge Devices at Risk Citrix has released fixes for two NetScaler vulnerabilities that security teams should review right away: CVE-2026-305...
AstraZeneca Data Breach: What You Need to Know
AstraZeneca Data Breach: What You Need to Know [Update] March 27, 2026: LAPSUS$ Releases AstraZeneca Data and Adds Virta Health A newly surfaced Dark Web post is drawing attention to an alleged AstraZ...
CVE-2025-32975: Quest KACE SMA SSO Authentication Bypass Enables Admin...
CVE-2025-32975: Quest KACE SMA SSO Authentication Bypass Enables Admin Takeover Quest KACE Systems Management Appliance (SMA) has a maximum-severity vulnerability, CVE-2025-32975, that allows an attac...
Crunchyroll Alleged Data Breach: What Do Users Need to Know?
Crunchyroll Alleged Data Breach: What Do Users Need to Know? Reports of a possible Crunchyroll (A popular anime streaming platform) data breach have drawn attention after claims surfaced that a threat...
