MAXHUB Pivot Client Application
MAXHUB Pivot client (pre-v1.36.2) exposes tenant emails due to hardcoded encryption keys—CVE-2026-6411, CVSS 7.3. Attackers can remotely decrypt sensitive data without authentication.
ACTIVE THREATS: Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks • Artifactory flaws chained in attacks deploying backdoor malware • Passkey-themed phishing attacks lead to Microsoft 365 data theft • Florida confirms DMV database breached via stolen police account • How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface ACTIVE THREATS: Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks • Artifactory flaws chained in attacks deploying backdoor malware • Passkey-themed phishing attacks lead to Microsoft 365 data theft • Florida confirms DMV database breached via stolen police account • How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Latest cybersecurity vulnerabilities news, analysis, and intelligence.
MAXHUB Pivot client (pre-v1.36.2) exposes tenant emails due to hardcoded encryption keys—CVE-2026-6411, CVSS 7.3. Attackers can remotely decrypt sensitive data without authentication.
PCPJack exploits five CVEs to steal credentials across cloud platforms and removes competing malware for control consolidation, signaling an evolution in cloud-focused threat campaigns. The framework targets container orchestration, cloud authentication, and privileged access vulnerabilities with mu
Ivanti EPMM faces active RCE exploitation (CVE-2026-6973, CVSS 7.2) affecting versions 12.6–12.8. Improper input validation allows authenticated admins to execute arbitrary code. Immediate patching required.
Chrome 148 patches 127 vulnerabilities, including critical integer overflow and use-after-free bugs that could enable arbitrary code execution. Deploy immediately to prevent exploitation.
Boost Security raised $4M for SDLC security as developers become primary attack targets. Early vulnerability fixes cost ~100x less than production ones, driving shift-left security adoption.
TrustFall is a critical vulnerability in AI code assistants (Claude Code, Cursor, Gemini, CoPilot) enabling arbitrary code execution through malicious GitHub repositories via inadequate security warnings—a significant supply chain attack risk for developers using these tools.
Incident response contracts create false confidence. Real readiness requires pre-positioned access, system documentation, and tested procedures established beforehand. Organizations without these waste critical hours when breaches occur.
Critical buffer overflow (CVE-2026-0300) in Palo Alto PAN-OS User-ID Portal allows unauthenticated root RCE from outside networks. The internet-facing design enables direct exploitation from the network perimeter. Active exploitation confirmed in April 2026.
Two Americans were sentenced to 18 months for operating "laptop farms" masking North Korean IT workers as U.S. employees at 70 companies, generating $200k+ for the regime in violation of sanctions.
DLP systems designed for email miss modern data loss—employees copy sensitive data from Salesforce to ChatGPT, bypassing traditional controls. Browser-based workflows have made DLP architecturally blind to actual data flows.
State-sponsored actors exploited a critical PAN-OS zero-day for approximately four weeks, enabling unauthenticated remote code execution with admin privileges on firewalls deployed globally. This compromise of a foundational security device affects government, finance, and critical infrastructure or
A 20-year-old was sentenced to 6.5 years for helping steal $250 million in cryptocurrency through home invasions and intimidation to coerce victims into surrendering digital assets. The case demonstrates how traditional organized crime tactics are merging with sophisticated digital theft to target c
Over a dozen critical vulnerabilities in vm2 allow attackers to bypass the Node.js sandbox and execute arbitrary code, breaking the isolation mechanism used by thousands of applications. These chained flaws represent a fundamental failure of one of JavaScript's most important security tools.
Meta outsourced smart glasses data to contractors and fired workers who protested. The scandal exposes privacy theater: corporations market privacy products without actual data protection controls.
New xlabs_v1 botnet targets exposed ADB ports to build DDoS-capable IoT networks using Mirai code. It highlights how legacy vulnerabilities remain critical security risks for IoT devices.
**A critical vm2 vulnerability allows complete sandbox escape and remote code execution on host systems. With 1M+ weekly downloads, this threatens thousands of Node.js applications globally.**
Cisco devices are vulnerable to a critical DoS flaw that crashes them with no automatic recovery. Remote attackers can trigger it, requiring manual intervention to restore functionality.
Herd Security secured $3M in funding to scale its AI-powered cybersecurity training platform, which automates the creation of personalized, engaging employee security awareness content. The capital will fuel expansion of training libraries and video generation capabilities, addressing the market's d
XBOW's $35M Series C extension shows investor confidence in autonomous penetration testing. The funding reflects enterprises' growing need for AI-driven security automation to scale security assessments beyond manual approaches.
AI agents are spreading through enterprises faster than governance can keep up. Companies lack visibility into what agents do, who deployed them, or what access they have—creating critical security gaps.
Critical incidents escalate due to broken response workflows, not detection gaps. Most organizations lack effective triage and coordination to act on alerts, despite generating massive visibility.
Security leadership determines whether penetration tests strengthen security or just check compliance boxes. Weak leadership causes undefined scope, access restrictions, and forgotten findings, preventing meaningful remediation.
UC Berkeley's CLTC helps under-resourced schools, nonprofits, and local governments defend against cyberattacks. Lacking security expertise, these organizations managing sensitive data are vulnerable.
Cybersecurity evolved from isolated breaches to nation-state operations, ransomware, and AI threats over two decades. Stuxnet exemplified the shift toward state-sponsored cyberweapons with kinetic impact, fundamentally reshaping how organizations defend critical infrastructure.
Attackers weaponized Windows Phone Link to deploy CloudZ RAT and Pheno malware for credential and OTP theft. The campaign exploits trusted Microsoft tools for persistent access with minimal forensic detection.
Google expanded Binary Transparency across Android with a public cryptographic ledger verifying apps are authentic and uncompromised on Google Play Store. This system protects against supply chain attacks, ensuring users receive exactly what Google intends to distribute.
Critical zero-day in Palo Alto Networks PAN-OS allows unauthenticated RCE via User-ID Authentication Portal and is actively exploited. Urgent patching required to prevent firewall compromise.
Oracle shifts to monthly critical security patches, abandoning its quarterly cycle to address vulnerabilities faster. This responds to industry pressure for quicker remediation of dangerous flaws.
Critical vulnerability CVE-2026-0300 in Palo Alto PAN-OS enables unauthenticated attackers to achieve remote code execution on firewalls and is actively exploited in the wild. With a CVSS score of 9.3, immediate patching is essential for all affected systems.
CVE-2026-0300 is a critical zero-day in Palo Alto Networks' firewalls actively exploited in the wild. Affecting thousands of enterprises, the unauthenticated vulnerability requires immediate patching.