TL;DR CVE-2026-50522 is a critical SharePoint RCE flaw rated CVSS 9.8. Researchers report active exploitation attempts, and...
News
TL;DR Apache has patched a critical OpenMeetings vulnerability tracked as CVE-2026-49488. The path traversal flaw grants arbitrary...
At a glance Threat actor Project CAV3RN cluster; linked to OilRig (APT34) with low confidence Activity type...
OEMs Discuss Secure Boot Challenges Last week, Microsoft invited enterprise IT administrators to a technical community exchange....
European cloud provider OVH just published a candid retrospective on its emergency patch campaign. The post explains...
At a glance Malware family TuxBot v3 Evolution (also tracked as Akiru) Threat actor Suspected link to...
Initial Attack Details The renowned open-source private cloud software, Nextcloud, suffered a cyberattack yesterday morning. This incident...
Anthropic quietly reshaped its Claude Team offering this week. The update lowers the entry barrier rather than...
At a Glance Actor Russian-speaking solo actor using the handle “bandcampro” Activity type AI-assisted C&C botnet, password...
At a glance Malware family ClickLock Stealer (new, named by Group-IB) Threat actor Unattributed. No actor or...
The White House has launched the GOLD EAGLE initiative, a new clearinghouse for cybersecurity vulnerability coordination. It...
During June 2026, Arctic Wolf Labs traced several ransomware intrusions to one entry point. Attackers exploited a...
Owners of LG monitors recently discovered something unwelcome on their desktops. Their displays had silently triggered the...
Attackers are already dropping webshells on WordPress sites through a flaw in WordPress Core itself. The bug...
At a glance Actor / group Piracy site operators. Four alleged members of “Los Ciberinfiltrados” arrested in...
TL;DR A critical Gitea vulnerability, CVE-2026-58443 (CVSS 9.6), lets a public-only token push commits into a private...
At a Glance Field Detail Actors UNK_pyreq2323 and UNK_OutFlareAZ (two independent, unattributed clusters) Activity Account enumeration and...
TL;DR The Apache Doris project has patched a critical Apache Doris vulnerability, tracked as CVE-2026-58319. Some Frontend...
TL;DR Siemens has patched a maximum-severity Opcenter X authentication bypass, tracked as CVE-2026-56451. The flaw scores 10.0...
At a glance Malware family HOLLOWGRAPH, linked with high confidence to the Cavern backdoor framework Threat actor...
At a Glance Field Detail Malware family CrashStealer (native C++ macOS infostealer) Threat actor Unattributed; part of...
Operation ShadowRecruit targets Indian job seekers with SheetAgent RAT, abusing ControlR and Google Sheets for C2. Seqrite...