Azure Cosmos DB's Gremlin flaw let Wiz escape the sandbox and retrieve an account key. Microsoft found no unauthorized ...
Oracle Critical Patch Update July 2026 closes the PeopleSoft CVE chain ShinyHunters used to breach 300 servers across ...
"There is zero doubt that the NSA believed that our voting databases were hacked and stolen." John Solomon reports that China utilized an advanced cyber intelligence group that bypasses legal channels ...
Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large ...
Threat actors are exploiting a medium-severity vulnerability in the Gravity SMTP WordPress plugin to steal complete system details, Defiant warns. Gravity SMTP for WordPress is an email deliverability ...
Security researchers at Cybernews discovered on June 12 what they describe as one of the largest credential databases ever left exposed online — a publicly accessible Elasticsearch cluster holding 24 ...
An emerging wave of rather concerning online theft is leveraging one of the Fintech sector’s most widely used platforms in order to conceal and reportedly distribute malicious code designed to harvest ...
An unknown threat actor has leveraged a large language model agent to conduct a swift, automated cyberattack, Sysdig reported after observing the incident on May 10, 2026. The attack began with the ...
All Linux kernels released after 2017 are vulnerable to critical privilege escalation bugs. A tiny 732-byte exploit grants root privileges across all major Linux distributions, with containerized ...
A researcher released a working ‘BlueHammer’ Windows zero-day exploit that could impact over 1 billion devices, granting SYSTEM-level access and leaving no patch yet. A disgruntled security researcher ...
Hackers are running a large-scale campaign to steal credentials in an automated way after exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js apps. At least 766 hosts across various cloud ...
Threat actors have demonstrated just how quickly they operate today after exploiting a critical open source vulnerability within 20 hours, working only from the advisory description. The bug, CVE-2026 ...