Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
500 stories published
CISO Conversation: Ping Identity's Russ Kirby on Leadership, Passion, and Pragmatism
Ping Identity CISO Russ Kirby shares insights on career progression, pragmatic incident response, and hiring enthusiastic security talent over certifications.
Aug 4, 2026Decades-Old IPMI Vulnerability Exposes Over 24,000 BMC Interfaces Online
A 20-year-old flaw in IPMI 2.0 (CVE-2013-4786) allows remote attackers to extract password hashes from internet-exposed server management interfaces.
Aug 4, 2026Google ADK Vulnerabilities Allowed Agent-to-Agent Prompt Injection and RCE
Security researchers discovered agent-to-agent prompt injection flaws in Google’s Agent Development Kit for Python, enabling remote code execution.
Aug 4, 2026Microsoft Bug Bounty Program Payouts Top $20 Million as AI Research Accelerates
Microsoft paid over $20 million to security researchers between July 2025 and June 2026, driven by AI-assisted vulnerability research and supply chain bounties.
Aug 4, 2026Russian Hackers Hijack Hotel Wi-Fi Networks to Steal Microsoft 365 Accounts
Microsoft links the CaptiveCrunch campaign targeting hotel Wi-Fi to Midnight Blizzard, using custom Go and PowerShell malware to compromise M365 accounts.
Aug 4, 2026New York Allocates $9M for Water Sector Security Following Multi-State OT Attacks
New York awards $9 million to 153 water and wastewater utilities after a coordinated campaign targeted internet-exposed PLCs across multiple states.
Aug 4, 2026Anthropic Claude Attacks Driven by System Over-Permissioning, Not Model Vulnerabilities
Anthropic reports recent security incidents involving Claude AI models were caused by over-permissioning and network access gaps rather than model flaws.
Aug 3, 2026N-able RMM Vulnerability Exploited to Grant Admin Privileges
Threat actors are actively exploiting a patch bypass flaw (CVE-2026-18577) in N-able RMM servers to gain unauthorized administrative access.
Aug 3, 2026Researchers Launch Tool to Trace AI-Generated Videos Back to Source
Security researchers have introduced a new detection tool aimed at tracing AI-generated video back to its source model and architecture.
Aug 3, 2026N-able RMM Servers Targeted via CVE-2026-18577 Authentication Bypass
Attackers are actively exploiting CVE-2026-18577, an authentication bypass flaw in N-able RMM servers, to gain administrative control.
Aug 3, 2026Fake Roblox Xeno Script Launcher Delivers Multi-Stage Java RAT and Infostealer
Threat actors are distributing a trojanized Roblox Xeno script executor that drops a Java-based RAT capable of webcam spying and credential theft.
Aug 3, 2026DOUBLECUP ClickFix Service Hides Malware in Browser Cache Steganography
The DOUBLECUP ClickFix service uses browser cache steganography to infect Windows and macOS systems with CountLoader and DeviceManager RAT.
Aug 3, 2026No news matches your search.