The Apache Polaris project, a popular open-source catalog for Apache Iceberg, has released a major security update...
Cloud Security
Independent security researcher Jakob Wolffhechel has publicly disclosed 89 vulnerabilities impacting Citrix XenServer/Hypervisor and its open-source counterpart,...
A sophisticated new threat actor, UNC6692, is redefining the art of the initial breach. According to a...
Researchers from The DFIR Report recently discovered an exposed command-and-control server that provided a rare look into...
On April 21, 2026, a high-severity Server-Side Request Forgery (SSRF) vulnerability was disclosed in LMDeploy, a popular...
The Python ecosystem is reeling from a sophisticated supply chain attack targeting Xinference (Xorbits Inference), a widely...
A pair of critical remote code execution (RCE) vulnerabilities has been disclosed in Spinnaker, the heavyweight open-source...
The prominent software conglomerate Atlassian has recently revised its data contribution policy, announcing that effective August 17,...
In the high-stakes world of cloud security, the promise of Confidential Computing is simple: your data should...
The threat group known as Triad Nexus has successfully bypassed international sanctions to reinstate a global fraud...
In the world of cloud-native security, OAuth2 Proxy serves as a vital gatekeeper, providing a flexible and...
In the modern enterprise, the Single Sign-On (SSO) portal is the master key to a company’s digital...
A significant security vulnerability has been identified in MinIO, the high-performance, S3-compatible object storage solution widely used...
In the modern landscape of Microsoft 365 security, the most dangerous threat might not be a sophisticated...
A sophisticated new threat has been unmasked targeting the heart of enterprise cloud infrastructure. Researchers from Breakglass...
In the complex machinery of cloud identity management, a single misinterpretation of data can lead to a...
Juju, the popular open-source application orchestration engine, is facing a critical security emergency. A newly discovered vulnerability,...
A critical security vulnerability in Axios, the ubiquitous promise-based HTTP client for Node.js and the browser, has...
Amazon Web Services (AWS) has released urgent security updates for its Research and Engineering Studio (RES), an...
A significant security vulnerability has been uncovered in OpenStack Keystone, the identity service that serves as the...
AWS has issued a high-severity security advisory for Firecracker, the open-source virtualization technology purpose-built for high-scale, multi-tenant...
Cisco Talos has revealed a major automated credential harvesting campaign, tracked as UAT-10608, that has already compromised...