Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
500 stories published
Metabase Zero-Day Exploited in Wild Grants Unauthenticated Admin Access
Metabase has patched a CVSS 10.0 zero-day SQL injection flaw impacting version 1.58+ that allows unauthenticated remote administrative access.
Aug 8, 2026Water Utilities Partner with DEF CON Franklin to Launch Water Watch Center
The National Rural Water Association and DEF CON Franklin launched the Water Watch Center to provide free MDR and threat intelligence to rural utilities.
Aug 7, 2026Metabase SQL Injection Zero-Day Exploited in Customer Data Theft Attacks
A critical unauthenticated Metabase SQL injection zero-day with a 10.0 CVSS score was exploited to steal customer data from Framework, Tally, and LexisNexis.
Aug 7, 2026Nearly 800 Malicious npm Packages Deliver Cross-Platform RATs and Infostealers
A massive npm supply chain campaign uses AI-generated typosquatting packages to deploy cross-platform malware and Sliver C2 across dev environments.
Aug 7, 2026Meta Ordered to Pay $567M and Restrict Youth Usage in Landmark New Mexico Decision
A New Mexico judge ordered Meta to pay $567 million and enforce strict platform limits over harms to youth on Instagram and Facebook.
Aug 7, 2026QuickFox VPN Supply Chain Compromise Delivers FDMTP Implant to Windows Users
Threat actors modified QuickFox VPN installers to profile Windows systems, skipping casual gamers to drop the FDMTP implant on dev and crypto hosts.
Aug 7, 2026Irregular AI Misconfigurations Exposed Internet Targets to Autonomous Hacking Models
Cybersecurity evaluation firm Irregular misconfigured testing sandboxes, allowing AI agents from Anthropic, OpenAI, and Meta to compromise real systems.
Aug 7, 2026North Carolina Ports Cyberattack Disrupts Logistics at Wilmington and Inland Hubs
A major North Carolina Ports cyberattack caused systems-wide outages, delaying container gates and operations across Wilmington and Morehead City facilities.
Aug 7, 2026Levi Strauss Discloses Data Exfiltration Following Social Engineering Attack
Levi Strauss & Co. has disclosed a corporate data breach after social engineering attackers compromised three employee laptops to exfiltrate company files.
Aug 7, 2026Microsoft 365 AitM Phishing Campaign Targets Payroll and Finance Emails
Arctic Wolf details an M365 AitM phishing campaign using multi-stage redirects, residential proxies, and Graph API abuse to harvest payroll emails.
Aug 7, 2026UNC6671 Rebrands Vishing Extortion Operation After $10 Million Ransom Spree
Vishing group UNC6671 has rebranded from BlackFile to Redact, Pink, Helix, and Falcon, targeting M365 and Okta with AiTM MFA-bypass attacks.
Aug 7, 2026Microsoft and Apple Patch Critical Cloud, Active Directory, and macOS Flaws
Microsoft patched multiple CVSS 10.0 flaws across Azure, Entra, and Teams, while Apple issued fixes for a macOS Screen Sharing authentication bypass.
Aug 7, 2026No news matches your search.