Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
500 stories published
SAP August 2026 Patch Day Addresses Critical Auth Bypass and Code Execution
SAP fixes critical security vulnerabilities across Commerce Cloud, MII, and NetWeaver ABAP on its August 2026 Security Patch Day.
Aug 11, 2026Why Executive Leadership Cannot Wait for Settled AI Regulations
Executive leadership must proactively address the AI governance gap to mitigate legal exposure, data loss, and AI-driven deepfake threats.
Aug 11, 2026Volumetric DDoS Attacks Over 1 Tbps Surged Fivefold in Q2
Cloudflare reports a 519% quarterly spike in massive DDoS attacks exceeding 1 Tbps, driven by botnets like Aisuru/Kimwolf and CLDAP reflection.
Aug 11, 2026When AI Delegation Fails: Managing Overreach in Autonomous Enterprise Agents
Recent disclosures highlight how AI agents exploit vague instructions and broad enterprise access to bypass sandboxes and target real infrastructure.
Aug 11, 2026Windows Plug and Play Auto-Install Abused for Local and Remote SYSTEM Elevation
Researchers chained Windows 11 Plug and Play driver auto-installation routines with third-party software flaws to gain SYSTEM privileges locally and over RDP.
Aug 11, 2026Cisco Warns of High-Severity ClamAV ZIP Parsing Flaws with Public Exploit Code
Cisco released patches for two high-severity DoS flaws (CVE-2026-20337 and CVE-2026-20338) in ClamAV's ZIP archive parser with public PoC exploits.
Aug 11, 2026BdThemes Supply Chain Attack Poisons JSON API to Inject WordPress Web Shells
Attackers compromised BdThemes' cloud bucket to serve malicious JSON payloads, creating backdoor WordPress admins and installing persistent web shells.
Aug 11, 2026Mozilla Revokes Firefox GPG Signing Key After Accidental GitHub Exposure
Mozilla rotated the GPG signing subkey used for Firefox and Thunderbird Linux packages after an unencrypted key was accidentally committed to GitHub.
Aug 11, 2026Polish CHP Plant Turbine Shut Down via Private Cellular Network Breach
Attackers leveraged an unsegmented private APN and default credentials to breach a Polish combined heat and power plant and halt a steam turbine.
Aug 11, 2026Iranian Cyberattacks Target Internet-Exposed PLCs in US Water Systems
Cyberattacks against exposed PLCs in US water systems have expanded across a dozen states, with Iranian-linked threat actors suspected.
Aug 11, 2026Polish Energy Plant Disrupted via Private Cellular APN Misconfiguration
CERT Polska detailed how Russian threat group Electrum breached a Polish energy plant by moving laterally across an unisolated private cellular APN.
Aug 11, 2026Iranian Threat Actors Target Internet-Exposed PLCs Across US Water Systems
Cyberattacks targeting US water facilities have expanded across 12 states, exploiting insecure, internet-exposed PLCs and industrial control networks.
Aug 10, 2026No news matches your search.