Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
Iran-linked hackers force a UK power plant offline for four days, a critical CVSS 9.3 authentication bypass hits Citrix NetScaler ADC and Gateway, and a third-party software flaw exposes SickKids Hospital employee data back to 2016.
Read source →Check Point weaponizes Microsoft Defender's own boot-time driver for kernel access, 9,300+ leaked AWS keys are still valid years later, Sakura Internet discloses a 1.36M-account breach, and a ransomware actor poses as a recovery firm.
Read source →Five U.S. agencies warn of AI-generated exploit scripts hitting Siemens S7 PLCs, CISA adds an actively exploited MLflow SSRF flaw to its KEV catalog, and a Rust supply-chain attack poisoned three widely used crates with build-time malware.
Read source →A CVSS 10.0 pre-auth flaw in Microsoft Entra ID was exploited before Microsoft's silent fix, CISA flags two actively exploited TrueConf Server bugs tied to trojanized installers, and a Copilot Personal flaw let one click exfiltrate connected accounts.
Read source →CISA adds four actively exploited flaws in Apple macOS, SharePoint, VMware vCenter, and Windows IKE to its KEV catalog, a Heights Finance breach exposes Social Security numbers for 1.2 million loan customers, and a healthcare data breach at CareCloud grows to 3.7 million patient records.
Read source →A cyberattack forces UT San Antonio to delay its fall semester for 42,000 students, a SafePal order-tracking flaw exposes nearly 40,000 crypto customers, and Questel confirms a vishing-driven Microsoft 365 breach ShinyHunters says yielded 21 million records.
Read source →GitLab ships an emergency patch for an unauthenticated GraphQL flaw that could wipe public projects, a pre-auth RCE hits 600,000 Forminator WordPress sites, Pokémon Center notifies UK and German shoppers after a logistics-vendor breach, and an unfixed Unisoc modem flaw hands over Android kernel access through a video call.
Read source →GeoServer finally ships a fix for its actively exploited SQL injection zero-day, a dark-web seller is auctioning Azure-tenant employee records from McDonald's and Vodafone, Clop names Shell among 43 new Windchill victims, and a hacktivist group trojanizes TrueConf installers with a custom backdoor.
Read source →SAP Commerce Cloud's max-severity flaw and an unpatched GeoServer zero-day are both under active attack, a patched macOS Screen Sharing bug is already mining Monero, RingCentral's ShinyHunters data lands in HIBP, and Apple's spyware alerts hit 110 countries.
Read source →A SharePoint JWT auth-bypass chain is under active exploitation with 8,500+ servers exposed, Beacon CRM's breach traces back to a leaked AWS key in public JS code, Claude watermark removers flood GitHub within days of rollout, and the EU's privacy watchdog pushes back on Europol's data-power expansion.
Read source →