Numerous Dropbox users recently received security notices stating that their accounts had been accessed without authorization between...
Account Takeover
TL;DR Attackers began targeting an Adobe Commerce vulnerability, CVE-2026-71362, within hours of its disclosure. The flaw scores...
TL;DR A critical flaw in TranslatePress lets unauthenticated attackers steal an administrator’s password reset link. Attackers can...
A critical flaw in the EverShop software allows complete unauthenticated account takeover attacks. Tracked as CVE-2026-72843, this...
TL;DR Keycloak 26.7.2 fixes five flaws, released on August 19, 2026. The most severe, CVE-2026-18963, allows a...
TL;DR CISA disclosed eight vulnerabilities in the Mira Hormone Monitor and its Android app. The worst, CVE-2026-68067,...
TL;DR WSO2 disclosed four critical vulnerabilities across its API and identity products. Several are WSO2 account takeover...
TL;DR: Attackers are actively exploiting a N-central account takeover flaw tracked as CVE-2026-18577. N-able says an incomplete...
TL;DR A critical Kimai vulnerability, CVE-2026-52824 (CVSS 9.1), affects the open-source time-tracking app’s official Docker image. The...
TL;DR Zoom has patched four flaws across its Windows products. The most severe Zoom vulnerability, CVE-2026-53412 (CVSS...
At a Glance Actor O-UNC-066 (Okta); tracked as CL-CRI-1147 / “Pink” by Palo Alto Unit 42; linked...
TL;DR A critical Better Auth SSRF flaw, tracked as CVE-2026-53513, lets any logged-in user reach internal services....
Ghost released version 6.37.0 to fix a critical cache poisoning bug. The Ghost cache poisoning flaw, tracked...
TL;DR A critical flaw in Poweradmin lets attackers take over DNS administrator accounts. Tracked as CVE-2026-54588, it...
TL;DR Zoho Corporation disclosed a critical ManageEngine account takeover flaw tracked as CVE-2026-11374. This CVSS 9.0 vulnerability...
A clever new phishing technique skips the password entirely. ReversingLabs has uncovered an active device code phishing...
A critical phpBB authentication bypass is putting countless online communities at risk right now. The flaw, tracked...
Budibase, the popular open-source operations platform known for saving engineers hundreds of hours building secure Agents, Apps,...
Sentry, the widely used application monitoring and error-tracking platform, has disclosed a critical vulnerability in its SAML...
Comet Backup, a prominent provider of secure backup software for IT professionals and global businesses, has issued...
A security vulnerability has been identified in Temporary Login, a popular WordPress plugin designed to provide secure,...
AVideo, a versatile video streaming platform popular among content creators and businesses for hosting and monetizing content,...