Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
500 stories published
Metabase Patches Critical Zero-Day SQL Injection Vulnerability
Metabase has released urgent patches for an unauthenticated SQL injection vulnerability exploited as a zero-day to gain administrative control.
Aug 10, 2026CISA Mandates Immediate Patch for Actively Exploited Progress LoadMaster RCE Flaw
CISA has added CVE-2026-8037, a critical root-level RCE vulnerability in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities catalog.
Aug 10, 2026CISA Warns of Actively Exploited Progress Kemp LoadMaster Flaw CVE-2026-8037
Active exploitation of a critical Progress Kemp LoadMaster command injection vulnerability (CVE-2026-8037) prompts urgent federal patching mandates.
Aug 10, 2026OpenAI Pauses Internal Astra Work Over Advanced Autonomous Cyber Capabilities
OpenAI has paused internal work on its upcoming Astra model after evaluations revealed potential Critical-level autonomous cyber capabilities.
Aug 10, 2026Malicious Solidity Pro VS Code Extensions Steal Crypto Wallets and API Keys
Malicious VS Code extensions targeting Web3 developers deliver info stealers, bypass market controls, and harvest crypto wallets and credentials.
Aug 10, 2026Critical Vulnerabilities Exposed in Belgian eID Software Used by Millions
Severe flaws in Nitro's Connective eID software allowed remote signature forgery, identity theft, and code execution across Belgian banks and agencies.
Aug 10, 2026Head Mare Hackers Trojanize TrueConf Server Installers to Deploy Backdoors
Unpatched TrueConf video conferencing servers are being exploited by Head Mare to distribute trojanized client updates carrying PhantomCore malware.
Aug 8, 2026Head Mare Trojanizes TrueConf Server Installers to Deploy Backdoors
Hacktivists exploit unpatched TrueConf video conferencing servers to swap client installers with backdoor malware and compromise enterprise networks.
Aug 8, 2026Critical One-Click RovoBlast Vulnerability Exposed Atlassian Rovo Enterprise Data
Varonis disclosed RovoBlast, a critical parameter-to-prompt injection flaw in Atlassian Rovo AI that enabled automated enterprise data exfiltration.
Aug 8, 2026Webmail CSS Attacks Allow Password Theft, UI Hijacking, and AI Exploitation
PortSwigger research shows how HTML and CSS in webmail can escape message containers to steal credentials, hijack UI actions, and manipulate AI agents.
Aug 8, 2026Atlassian Rovo Vulnerabilities Allow Indirect Prompt Injection and Data Theft
Two flaw paths in Atlassian Rovo let attackers trick the AI assistant into exfiltrating sensitive Jira and Confluence data to external servers.
Aug 8, 2026N-able Issues Emergency N-central Hotfix 2 Amid Active Tunneling Attacks
N-able released Hotfix 2 for N-central vulnerability CVE-2026-18577 as attackers breach managed endpoints and install persistent Cloudflare Tunnels.
Aug 8, 2026No news matches your search.