Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
500 stories published
Critical Pre-Auth RCE CVE-2026-58138 in Orkes Conductor Under Active Attack
Attackers are actively exploiting a critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor workflow servers.
Sep 19, 2026Dark Reading Hosts Cybersecurity Outlook 2027 Virtual Event
Dark Reading is hosting its Cybersecurity Outlook 2027 virtual event to help security teams prepare for long-term threat trends, AI risks, and defense…
Sep 19, 2026CISA Adds Three Actively Exploited Linux Kernel Vulnerabilities to KEV
CISA has added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its KEV catalog following confirmed active attacks.
Sep 19, 2026Claude-Generated Exploit Chained to Hijack OpenAI Accounts and GitHub Repos
Security researchers used Anthropic's Claude to exploit a libheif flaw in Discourse, hijacking OpenAI ChatGPT accounts and reaching internal repos.
Sep 19, 2026Gyazo Data Breach Exposes 23 Million User Records via Upload Server Flaw
A server vulnerability in Gyazo's image upload infrastructure allowed attackers to steal 23.6 million user records and 490 million metadata items.
Sep 18, 2026Brevo Supply Chain Attack Injects ClickFix Malware Into 100,000 Websites
A breach at marketing platform Brevo allowed attackers to deploy malicious Cloudflare Workers, serving ClickFix scams and backdooring WordPress sites.
Sep 18, 2026AI Agent Breaches Spanish Organization and Alters Personal Data
An AI agent has breached a Spanish organization and altered personal data, marking a significant shift toward autonomous cyberattacks.
Sep 18, 2026Check Point Fixes Critical Pre-Auth Root RCE in Security Management Servers
Check Point released LivePatch sk1000155 for CVE-2026-91843, a critical pre-auth stack overflow allowing remote code execution as root on management nodes.
Sep 18, 2026Cisco Patches Maximum-Severity ISE Zero-Day Under Active Attack
Cisco has issued emergency patches for CVE-2026-76460, a CVSS 10.0 authentication bypass in Identity Services Engine actively targeted in the wild.
Sep 17, 2026Cisco Warns of Maximum-Severity ISE Zero-Day Exploited in Active Attacks
Cisco has issued an urgent advisory for a zero-day authentication bypass in Cisco Identity Services Engine (CVE-2026-76460) under active exploitation.
Sep 17, 2026Cisco Patches Maximum-Severity ISE Zero-Day Exploited in the Wild
Cisco has released software patches for an actively exploited API authentication bypass zero-day (CVE-2026-76460) in Cisco Identity Services Engine.
Sep 17, 2026Google Patches Actively Exploited Pixel Cellular Modem Zero-Day CVE-2026-58704
Google has released September 2026 updates fixing CVE-2026-58704, an actively exploited zero-day flaw in Pixel cellular modem firmware.
Sep 17, 2026No news matches your search.