Get your free weekly report by email.
Researchers identified a coordinated supply chain malware campaign named TrapDoor, involving waves of malicious packages across npm, PyPI, and Crates.io. Public reports tie the activity to credential ...
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the ...
Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct ...
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it. Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A ...
The SOCRadar Dark Web Team has detected a new claim of a massive data leak targeting Banco Vimenca. Threat actors have announced that the full set of the bank’s confidential data has been released on ...
Cisco has confirmed active exploitation of CVE-2026-76461, a critical SQL injection vulnerability in Cisco Secure Email Gateway that can lead to operating-system command execution with root privileges ...
CVE-2026-48558 is a critical authentication bypass affecting SimpleHelp, a remote support and RMM (remote monitoring and management) platform often used for technician access into managed environments ...
MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a ...
Ransomware attack on Anery Home Care, attributed to Lockbit. Domain, industry, country, and victim status tracked in real time.
Ransomware attack on Markisol Group, attributed to Thegentlemen. Domain, industry, country, and victim status tracked in real time.
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is ...