Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
286 stories published
Critical Vulnerabilities Patched in Ubiquiti UniFi OS Ecosystem
Ubiquiti has released critical security updates addressing seven severe vulnerabilities in its UniFi OS, including a maximum-severity command injection flaw…
Jul 9, 2026AssuranceAmerica Data Breach Exposes 6.9 Million Driver's Licenses
A cyberattack on AssuranceAmerica compromised data for 6.9 million individuals, including driver's license numbers and other sensitive information.
Jul 9, 2026CISA Warns of Active Exploitation of Langflow IDOR for Credential Harvesting
CISA has added an Insecure Direct Object Reference (IDOR) vulnerability in Langflow (CVE-2026-55255) to its KEV catalog due to active exploitation.
Jul 9, 2026China-Aligned Hackers Exploit Roundcube Vulnerabilities in University Attacks
A suspected China-aligned APT group is actively exploiting patched Roundcube flaws (e.g., CVE-2024-42009) targeting U.S. and Canadian universities.
Jul 9, 2026Critical Gitea Authentication Bypass Under Active Exploitation
A critical vulnerability in Gitea (CVE-2026-20896) allows authentication bypass and is being actively exploited in the wild.
Jul 9, 2026KDDI Email Platform Breach Exposes 12 Million User Credentials
A zero-day vulnerability in a third-party email platform led to the exposure of 12 million email addresses and passwords from Japanese ISPs, including KDDI.
Jul 9, 2026BeyondTrust Fixes Multiple Critical Vulnerabilities in Remote Access Products
BeyondTrust has released security updates addressing critical vulnerabilities in its Remote Support and Privileged Remote Access products.
Jul 9, 2026Microsoft Patches "RoguePlanet" Local Privilege Escalation in Defender
Microsoft has released a patch for CVE-2026-50656, a privilege escalation vulnerability in Microsoft Defender's Malware Protection Engine.
Jul 9, 2026Critical 15-Year-Old Linux Kernel Vulnerability "GhostLock" Grants Root Access
A newly disclosed 15-year-old Linux kernel flaw (CVE-2026-43499) allows local users to achieve root privileges and escape containers.
Jul 9, 2026Accenture Confirms Data Breach After Source Code and Credentials Stolen
A hacker claims to have stolen 35GB of sensitive data, including source code and access keys, from consulting giant Accenture.
Jul 9, 2026No news matches your search.