Ransomware group RansomHouse has listed Trellix, the enterprise cybersecurity giant formed from the merger of McAfee Enterprise...
Cyber Attack
A critical cross-origin WebSocket hijacking vulnerability (CVSS 9.7) in Cline’s local kanban server, one of the most...
Days after confirming one of the largest data breaches in education technology history, Instructure is now facing...
A critical ServiceAccount impersonation bypass in Rancher Fleet (CVSS 9.9) allows any tenant with git push access...
A critical, unpatched local privilege escalation (LPE) vulnerability dubbed Dirty Frag has been publicly disclosed, enabling any local attacker...
A high-severity vulnerability (CVE-2026-41139) in the popular mathjs JavaScript library allows remote attackers to execute arbitrary JavaScript...
Kaspersky’s GReAT team has uncovered a sophisticated PyPI supply chain attack attributed with moderate confidence to the...
An uncovered five malicious NuGet packages published under the threat actor account bmrxntfj that typosquat widely used Chinese .NET...
A critical-severity argument-injection vulnerability, tracked as CVE-2026-40281 and covered in the advisory GHSA-q7r4-hc83-hf2q, has been disclosed in Gotenberg, a widely used...
A critical zero-day vulnerability in its PAN-OS firewall operating system, tracked as CVE-2026-0300, that is already being...