
Latest coverage
Everything we've published, newest first. 86 articles across threats, news, research, analysis and guides.
ThreatsTechnology, Cloud & SaaSHighPriya Raman7 min read
ThreatsTechnology, Cloud & SaaSCriticalCISA Mandates Remediation for ownCloud Improper Authentication Flaw Under Active Exploitation
Aisha Noor7 min read
ThreatsTechnology, Cloud & SaaSCriticalCISA Adds Critical Linux Kernel IPv6 Privilege Escalation Flaw to KEV Catalog
Daniel Okafor8 min read
ThreatsIndustrial, OT & IoTCriticalCISA Discloses Critical Vulnerabilities in Rockwell Automation Logix Controllers & 1756 Modules
Mei-Lin Chen7 min read
ThreatsEnergy & UtilitiesHighCISA Alerts Critical Energy Sector to High-Severity Flaws in AVEVA Pipeline Integrity Monitor
Daniel Okafor8 min read
ThreatsHealthcare & PharmaBreakingCISA Warns of Critical RCE Flaws in NextGen Mirth Connect Threatening Hospital HL7 Pipelines
Priya Raman8 min read
IndustryGovernment & DefenceHighCISA Finalizes CIRCIA Mandate: 72-Hour Incident and 24-Hour Ransomware Reporting Enforced
Tom Verhoeven8 min read
ResearchTechnology, Cloud & SaaSHighCISA, NSA, and FBI Warn Critical Infrastructure of Advanced AI Model Extraction Campaigns
Daniel Okafor9 min read
ThreatsIndustrial, OT & IoTCriticalSAP Security Patch Day Addresses Critical NetWeaver Message Server Authentication Bypass
Aisha Noor8 min read
NewsBanking & FintechHighCERT-In Warns of Massive Android Smishing Campaign Masquerading as Traffic E-Challans
Mei-Lin Chen7 min read
ThreatsTechnology, Cloud & SaaSCriticalBroadcom Discloses Critical VMware Hypervisor Escape Flaws in Workstation and Fusion
Priya Raman8 min read
NewsTechnology, Cloud & SaaSCriticalGoogle September 2026 Android Bulletin Patches Critical System Zero-Click RCE Flaws
Mei-Lin Chen7 min read
ThreatsTelecom & MediaHighCisco Fixes High-Severity Memory Corruption Flaw in Carrier-Grade IOS XR Routing Core
Daniel Okafor7 min read
ThreatsTechnology, Cloud & SaaSBreakingIvanti Patches Critical Remote Code Execution Flaw in Neurons for ITSM Infrastructure
Priya Raman8 min read
ThreatsTechnology, Cloud & SaaSBreakingCitrix NetScaler CVSS 9.3 authentication bypass CVE-2026-19490 under active in-the-wild exploitation
Daniel Okafor6 min read
NewsGovernment & DefenceHighFlorida DMV confirms DAVID driver database breach after officer credentials compromised on personal device
Priya Raman5 min read
ResearchTechnology, Cloud & SaaSHigh'ShieldCrash' exploit bypasses Microsoft Defender patch, enabling local SYSTEM file access
Mei-Lin Chen7 min read
InsightsTechnology, Cloud & SaaSMediumEU Cyber Resilience Act reporting rules go live: Hardware and software vendors face mandatory 24-hour disclosures
Tom Verhoeven6 min read
NewsTechnology, Cloud & SaaSMediumMicrosoft September 2026 cumulative updates trigger Remote Desktop Services deadlock across Windows Server
Aisha Noor5 min read
ThreatsTechnology, Cloud & SaaSBreakingMicrosoft traces passkey-themed lures to persistent Microsoft 365 cloud compromise
Aisha Noor6 min read
ThreatsTechnology, Cloud & SaaSBreakingGitHub adds a merge gate for pull requests with unresolved secret alerts
Daniel Okafor5 min read- ThreatsRetail & E-commerceBreaking
Adobe warns of exploited Commerce and Magento RCE — patch CVE-2026-75650 now
Priya Raman6 min read
ThreatsTechnology, Cloud & SaaSBreakingCisco Secure FMC authentication bypass CVE-2026-20079 exploited by Qilin ransomware affiliates
Daniel Okafor6 min read
ThreatsTechnology, Cloud & SaaSCriticalSwarm of OpenAI agents flooded RubyGems to execute code and harvest data on RubyDoc servers
Mei-Lin Chen7 min read
ThreatsTelecom & MediaCriticalChinese state-aligned group UNC3569 exploited zero-day flaw in Sogou Input Method to drop GRAYRABBIT backdoor
Mei-Lin Chen6 min read
ThreatsTelecom & MediaHighAttackers exploit Google Play Early Access loop to distribute deceptive malware apps to millions
Aisha Noor5 min read
ThreatsTechnology, Cloud & SaaSCriticalThreat actors actively exploit Langflow AI orchestration flaws to steal cloud API keys and deploy miners
Priya Raman6 min read
InsightsBanking & FintechBreakingRBI drafts a time-bound debit-hold SOP for suspected money-mule accounts
Tom Verhoeven6 min read
NewsHealthcare & PharmaBreakingIDScan.net says customer information in cloud accounts may have been accessed
Priya Raman5 min read
ThreatsIndustrial, OT & IoTCriticalMikroTrick exploit chain compromises MikroTik RouterOS devices as ScreenConnect client flaw hits KEV
Daniel Okafor6 min read
InsightsTechnology, Cloud & SaaSBreakingOpenAI positions Daybreak as a governed loop for AI-assisted cyber defense
Priya Raman6 min read
ResearchGovernment & DefenceHighAnthropic says AI is moving from assistant to orchestrator in cyber operations
Mei-Lin Chen7 min read
ThreatsTechnology, Cloud & SaaSHighPostGREShell: 12-year-old PostgreSQL logical replication flaw CVE-2026-6471 enables remote code execution
Tom Verhoeven6 min read
ResearchTechnology, Cloud & SaaSCriticalGitSpawn flaws in AI coding agents execute arbitrary code from malicious repository configurations
Priya Raman7 min read
ThreatsGovernment & DefenceCriticalNorth Korean actors deploy trojanized HAProxy 'TED' backdoor inside South Korean enterprise networks
Daniel Okafor6 min read
ThreatsIndustrial, OT & IoTBreakingTwo 9.8 Check Point VPN flaws put the perimeter back on the emergency patch queue
Priya Raman5 min read
NewsBanking & FintechHighStreamRAT Android banking trojan targeted 570,000 European users through deceptive Meta streaming ads
Aisha Noor5 min read
ThreatsTechnology, Cloud & SaaSBreakingGitLab fixes maximum-severity CVSS 10.0 file-read flaw as in-the-wild exploitation begins
Priya Raman6 min read
ThreatsTechnology, Cloud & SaaSCriticalAttackers chain dual JFrog Artifactory vulnerabilities to hijack build pipelines and plant backdoors
Aisha Noor6 min read
NewsCrypto & Web3HighTrezor alerts 347,000 customers after third-party Brevo breach triggers targeted phishing wave
CST Newsroom5 min read
ThreatsTechnology, Cloud & SaaSHighPaperCut issues superseding maintenance releases as attackers deploy AI agent swarms against 440+ servers
Daniel Okafor6 min read
InsightsGovernment & DefenceCISA BOD 26-04 ends CVSS-ordered patching: the four questions that replace it
Priya Raman7 min read
InsightsTechnology, Cloud & SaaSMediumEntra ID's February 2027 Sign-In Block: A Dated Migration Plan for the Accounts That Will Break
Aisha Noor6 min read
ThreatsIndustrial, OT & IoTBreakingSonicWall SMA1000 Zero-Day Chain Hit CISA KEV in Three Days. Patching Is the Easy Part
Daniel Okafor5 min read
GuidesGovernment & DefenceMediumCERT-In's six-hour clock meets DPDP: one intake process, two notification deadlines
Tom Verhoeven6 min read- NewsGovernment & DefenceHigh
A CVSS 10.0 ERP Flaw Your Scanner Will Never Report: The CERT-In Blind Spot
CST Newsroom6 min read
ThreatsTechnology, Cloud & SaaSCriticalFortiClient EMS CVE-2026-35616: the hotfix window was not the dangerous part
Priya Raman6 min read
InsightsTechnology, Cloud & SaaSHighNearly 1 in 10 Exposed LiteLLM AI Gateways Leaked Master Admin Keys
Aisha Noor5 min read- ThreatsTechnology, Cloud & SaaSHigh
LiteLLM and Kestra in KEV: exploited AI tooling is now a vulnerability management problem
Daniel Okafor6 min read
ThreatsGovernment & DefenceCriticalCISA adds 12 exploited CVEs to KEV in a single week, spanning Citrix, Cisco and Fortinet
Daniel Okafor6 min read
ResearchEducation & AcademiaHighEight new ransomware brands in one week: why tracking group names has stopped working
Daniel Okafor6 min read
ThreatsBanking & FintechHighGigabud Android Banking Trojan Abuses Work Profiles to Evade Client-Side Detection
Mei-Lin Chen5 min read- ThreatsGovernment & DefenceHigh
APT28 Ran Its C2 Through Filen Cloud Storage. Reputation Filtering Never Stood a Chance
Mei-Lin Chen6 min read
InsightsTechnology, Cloud & SaaSHighSharePoint 2016/2019 is unpatchable now. Exchange has until 31 October.
Priya Raman6 min read
InsightsTechnology, Cloud & SaaSHighThe agentic AI security gap: 83% are deploying, 29% feel ready
Priya Raman8 min read
GuidesTechnology, Cloud & SaaSPlaybook: surviving a 900-CVE Patch Tuesday without breaking your change process
Priya Raman8 min read
ThreatsTechnology, Cloud & SaaSBreakingMicrosoft ships 973 fixes in September Patch Tuesday, two flaws already exploited
Priya Raman7 min read
ThreatsTechnology, Cloud & SaaSCriticalSAP OVERPASS: CVSS 10.0 Kernel Flaw Enables Pre-Auth Remote Code Execution
Priya Raman6 min read
InsightsEnergy & UtilitiesLowThe EU AI Act's High-Risk Rules Slipped to December 2027. Your Logging Problem Did Not Move
Tom Verhoeven6 min read
ResearchTechnology, Cloud & SaaSCriticalBlueMoon Exploit Kit: Chrome V8 Zero-Day Chained with Windows Kernel Escalation
Mei-Lin Chen6 min read
InsightsTechnology, Cloud & SaaSHigh88% Had an AI Agent Incident. 82% Believe Their Policy Covers It.
Priya Raman6 min read
ResearchTechnology, Cloud & SaaSCriticalDeepSeek Harness Vulnerability Allowed AI Coding Agents to Disable Their Sandbox
Mei-Lin Chen5 min read
ResearchEducation & AcademiaHighScreening Serpens shipped six RAT builds in ten weeks. The config file is what gives them away
Mei-Lin Chen6 min read
ThreatsTechnology, Cloud & SaaSCriticalN-able N-central Pre-Auth RCE Flaw Under Active Exploitation (CVE-2026-86218)
Daniel Okafor5 min read- ThreatsGovernment & DefenceHigh
Gunra ransomware: what AA26-222A actually gives your detection engineers
Daniel Okafor6 min read
GuidesIndustrial, OT & IoTPlaybook: hardening the edge appliance you cannot put an agent on
Aisha Noor7 min read
ThreatsIndustrial, OT & IoTCriticalPAN-OS authentication bypass CVE-2026-0257 puts firewall management planes at risk
Daniel Okafor6 min read
ThreatsBanking & FintechHighSlim Spider Targets Brazilian Instant Payments (Pix) and Crypto Custody Infrastructure
Daniel Okafor6 min read
ThreatsTechnology, Cloud & SaaSCriticalFreeIPA LDAP ACI Vulnerability Chain Grants Anonymous Clients Domain Admin Rights
Tom Verhoeven5 min read
InsightsEnergy & UtilitiesNIS2 simplification and CSA2: what the January 2026 cybersecurity package actually changes
Tom Verhoeven7 min read
NewsCrypto & Web3CriticalLiquid Network Elements Protocol Exploit Triggers 4,000 BTC Sidechain Drain
CST Newsroom6 min read
GuidesTechnology, Cloud & SaaSHardening guide: locking down your npm and CI/CD supply chain
Mei-Lin Chen9 min read
ResearchTelecom & MediaCriticalSalt Typhoon has compromised networks in more than 80 countries, researchers say
Daniel Okafor8 min read
InsightsTechnology, Cloud & SaaSMFA failed in 84% of incident responses. The problem is the session, not the factor
Aisha Noor7 min read- NewsHealthcare & PharmaCritical
Healthcare ransomware wave: OVP Health and ProHealth Medical hit within weeks
CST Newsroom5 min read
ResearchEducation & AcademiaBreakout time falls to 72 minutes — and most SOCs are not built for it
Priya Raman7 min read
ThreatsTechnology, Cloud & SaaSCriticalChainDrop worm spreads through hundreds of npm packages, stealing CI/CD secrets
Mei-Lin Chen8 min read- ThreatsTechnology, Cloud & SaaSHigh
Enterprise app CVE roundup: PeopleSoft, cPanel, Artifactory and Switchvox all need attention
Priya Raman6 min read
ResearchEducation & AcademiaHighAttackers impersonated hundreds of brands on GitHub to push malware through search results
Mei-Lin Chen6 min read
ThreatsTelecom & MediaCriticalCisco Nexus 9000 Silicon One Switches Exposed to Unauthenticated Root RCE
Daniel Okafor5 min read
ThreatsBanking & FintechHighInfostealers harvested 1.7 billion credentials in six months as Vidar and Lumma dominate
Mei-Lin Chen7 min read
InsightsBanking & FintechThe SEC’s four-day disclosure clock in practice: materiality is the hard part
Tom Verhoeven6 min read- NewsTechnology, Cloud & SaaSCritical
HostDZire ransomware encrypts ESXi virtual disks across three countries
Daniel Okafor6 min read - ThreatsBanking & FintechHigh
One AiTM phishing campaign compromised 35,000 users across 13,000 organisations in three days
Aisha Noor7 min read - NewsGovernment & DefenceHigh
Rhysida ransomware hits Berlin Senate network as public sector attacks accelerate
Daniel Okafor5 min read - NewsTransport & LogisticsHigh
CEVA Logistics cyberattack halts shipping across eight European warehouses
CST Newsroom5 min read