Multiple vendor-signed UEFI applications have been confirmed vulnerable to Secure Boot bypass attacks leveraging a “Bring Your...
Cyber Security News
A maximum-severity vulnerability in Splunk Enterprise has been disclosed and formally added to CISA’s Known Exploited Vulnerabilities...
A critical unauthenticated arbitrary file deletion vulnerability has been discovered in Avada Builder, one of WordPress’s most...
A critical-severity path traversal vulnerability (CVE-2026-8713) in the Avada (Fusion) Builder WordPress plugin allows unauthenticated attackers to...
Threat actors silently exfiltrated enterprise Salesforce CRM data by hijacking a trusted third-party OAuth integration, confirming that...
Microsoft Threat Intelligence has uncovered a sophisticated cryptocurrency clipper campaign dubbed CryptoBandits, active since February 2026, that combines...
Cisco has disclosed two severe vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector...
Splunk has disclosed two significant security vulnerabilities in its AI Toolkit, including a critical-severity OS command injection flaw that...
Microsoft has officially acknowledged a critical elevation-of-privilege zero-day vulnerability in the Microsoft Malware Protection Engine, tracked as...
A sophisticated supply-chain attack targeting WordPress plugin giant Awesome Motive has injected malicious JavaScript into CDN-served files...