New Cisco DoS flaw requires manual reboot to revive devices
Cisco devices are vulnerable to a critical DoS flaw that crashes them with no automatic recovery. Remote attackers can trigger it, requiring manual intervention to restore functionality.
ACTIVE THREATS: Orthanc DICOM Server • GitLab Vulnerability Exploited One Day After Disclosure • CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV • Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent • Phishing Research Challenges Conventional Security Awareness Testing ACTIVE THREATS: Orthanc DICOM Server • GitLab Vulnerability Exploited One Day After Disclosure • CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV • Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent • Phishing Research Challenges Conventional Security Awareness Testing
Latest cybersecurity vulnerabilities news, analysis, and intelligence.
Cisco devices are vulnerable to a critical DoS flaw that crashes them with no automatic recovery. Remote attackers can trigger it, requiring manual intervention to restore functionality.
Herd Security secured $3M in funding to scale its AI-powered cybersecurity training platform, which automates the creation of personalized, engaging employee security awareness content. The capital will fuel expansion of training libraries and video generation capabilities, addressing the market's d
XBOW's $35M Series C extension shows investor confidence in autonomous penetration testing. The funding reflects enterprises' growing need for AI-driven security automation to scale security assessments beyond manual approaches.
AI agents are spreading through enterprises faster than governance can keep up. Companies lack visibility into what agents do, who deployed them, or what access they have—creating critical security gaps.
Critical incidents escalate due to broken response workflows, not detection gaps. Most organizations lack effective triage and coordination to act on alerts, despite generating massive visibility.
Security leadership determines whether penetration tests strengthen security or just check compliance boxes. Weak leadership causes undefined scope, access restrictions, and forgotten findings, preventing meaningful remediation.
UC Berkeley's CLTC helps under-resourced schools, nonprofits, and local governments defend against cyberattacks. Lacking security expertise, these organizations managing sensitive data are vulnerable.
Cybersecurity evolved from isolated breaches to nation-state operations, ransomware, and AI threats over two decades. Stuxnet exemplified the shift toward state-sponsored cyberweapons with kinetic impact, fundamentally reshaping how organizations defend critical infrastructure.
Attackers weaponized Windows Phone Link to deploy CloudZ RAT and Pheno malware for credential and OTP theft. The campaign exploits trusted Microsoft tools for persistent access with minimal forensic detection.
Google expanded Binary Transparency across Android with a public cryptographic ledger verifying apps are authentic and uncompromised on Google Play Store. This system protects against supply chain attacks, ensuring users receive exactly what Google intends to distribute.
Critical zero-day in Palo Alto Networks PAN-OS allows unauthenticated RCE via User-ID Authentication Portal and is actively exploited. Urgent patching required to prevent firewall compromise.
Oracle shifts to monthly critical security patches, abandoning its quarterly cycle to address vulnerabilities faster. This responds to industry pressure for quicker remediation of dangerous flaws.
Critical vulnerability CVE-2026-0300 in Palo Alto PAN-OS enables unauthenticated attackers to achieve remote code execution on firewalls and is actively exploited in the wild. With a CVSS score of 9.3, immediate patching is essential for all affected systems.
CVE-2026-0300 is a critical zero-day in Palo Alto Networks' firewalls actively exploited in the wild. Affecting thousands of enterprises, the unauthenticated vulnerability requires immediate patching.
CVE-2026-0936 in ABB B&R PVI allows authenticated local attackers to extract credentials through plaintext client logging. The MEDIUM-severity flaw (CVSS 5.0) poses particular risk in industrial environments where logging is enabled for troubleshooting. Organizations must upgrade or strictly manage
Johnson Controls' CEM AC2000 has a critical privilege escalation flaw (CVE-2026-21661) that could compromise critical infrastructure security systems. Patches exist but many systems remain unpatched.
Hitachi Energy's PCM600 power control platform has a Zip-Slip path traversal flaw (CVE-2018-1002208) allowing local attackers to write arbitrary files. The vulnerability threatens data integrity across critical energy infrastructure systems globally.
ABB's B&R Automation Runtime has a critical race condition (CVE-2025-11044) allowing unauthenticated attackers to permanently disable industrial systems through resource exhaustion. The flaw requires no user interaction and ABB has released patches.
ABB B&R Automation Studio versions before 6.5 contain a critical certificate validation bypass vulnerability (CVE-2025-11043, CVSS 7.4) that allows network attackers to perform man-in-the-middle attacks. Attackers can intercept OPC-UA and ANSL communications to steal data and inject malicious comman
Apache patched critical RCE vulnerabilities in MINA networking library enabling unauthenticated remote code execution. Organizations using MINA must apply updates immediately to prevent system compromise.
Cargo theft evolved from street heists to supply chain cyberattacks. Criminals now compromise logistics systems to reroute shipments, enabling multimillion-dollar thefts with a few keystrokes.
Microsoft Edge stores plaintext passwords in process memory, exposing enterprise credentials to admin-level attackers. This vulnerability enables credential theft and lateral movement within corporate networks.
CVE-2026-23918: Apache HTTP/2 critical double-free flaw enables remote DoS and potential RCE. Requires only port 80/443 access; exploitable via crafted HTTP/2 frames.
Android patched CVE-2026-0073, a critical RCE vulnerability in its System component requiring no user interaction. It threatened millions of devices worldwide with complete device takeover.
Bleeding Llama exposes 300,000 Ollama deployments to unauthenticated remote memory theft via heap out-of-bounds read vulnerability, risking sensitive data leaks from AI systems worldwide.
Microsoft warns of a sophisticated phishing campaign using fake conduct reports and adversary-in-the-middle attacks to intercept credentials and session tokens, bypassing MFA protections. The attack demonstrates nation-state-level sophistication targeting US organizations.
FTC bans Kochava from selling location data on hundreds of millions of devices without explicit consumer consent. The settlement escalates regulatory scrutiny of data brokers.
CVE-2026-29014 is a critical flaw in MetInfo CMS enabling unauthenticated PHP code execution. Already under active exploitation, it requires no credentials or user interaction. Organizations must patch immediately.
A 2000s USB drop test became cybersecurity's defining lesson: employees' curiosity bypasses firewalls. The simple social engineering test proved human behavior, not technology, is security's weakest link.
Google raised Android exploit bounties to $1.5 million for critical vulnerabilities, but reduced payouts for AI-assisted discoveries by 10-50%, reflecting how automation is reshaping security research economics while rewarding pure human ingenuity over machine-assisted findings.