Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
500 stories published
Windows BitLocker Security Feature Bypass via Physical Access (CVE-2026-50661)
A publicly disclosed Windows BitLocker vulnerability (CVE-2026-50661) allows physical bypass of encryption and access to data.
Jul 19, 2026Citrix Secure Access Client Flaw Allows SYSTEM Privilege Escalation
A newly reported vulnerability in Citrix Secure Access Client for Windows allows low-privileged users to achieve SYSTEM privileges.
Jul 19, 2026Critical RCE and SQLi Vulnerabilities Patched in WordPress 7.0.2
WordPress 7.0.2 addresses two high-severity flaws, including RCE via REST API batch-route confusion and a facilitated SQL injection.
Jul 19, 2026Kenya President's Website Temporarily Offline Following Cybersecurity Incident
Kenya's presidential website was taken offline after a cybersecurity incident, with investigations underway to assess impact.
Jul 19, 2026New Starland RAT Steals Browser Credentials and Crypto Wallets
A newly discovered malware, Starland RAT, is actively targeting systems to exfiltrate browser credentials and cryptocurrency wallet data.
Jul 19, 2026Chained Zero-Days Grant Persistent Root Access in Siemens ROX II OT Switches
A chain of three zero-day vulnerabilities in Siemens ROX II OT industrial switches allows for persistent root access, impacting critical infrastructure.
Jul 18, 2026Critical Flaw Exposes Shark Robot Vacuum Cameras, Maps, and Wi-Fi
A critical vulnerability in Shark robot vacuums allows attackers to remotely access live camera feeds, stored home maps, and Wi-Fi passwords.
Jul 18, 2026New Windows LegacyHive Zero-Day Grants Admin Privileges
An unpatched Windows zero-day vulnerability, dubbed 'LegacyHive,' allows standard users to gain administrative privileges on Windows 10 and 11 systems.
Jul 18, 2026Critical WordPress Pre-Auth RCE and SQLi Vulnerabilities Patched, Public PoC Available
WordPress versions 6.9.0-6.9.4 and 7.0.0-7.0.1 are vulnerable to a pre-authentication RCE (CVE-2026-63030) and SQLi (CVE-2026-60137) with a public PoC now…
Jul 18, 2026New macOS Vulnerability Allows EDR/MDM Bypass and Security Agent Disablement
A new macOS vulnerability, "Faind My XPC," enables standard users to silently disable EDR, MDM, and security agents without kernel access or alerts.
Jul 18, 2026Critical SQL Injection Vulnerability in Sangoma Switchvox SMB Edition Disclosed
An unauthenticated SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox SMB Edition 8.3 allows remote code execution.
Jul 18, 2026Colombian Energy Giant Ecopetrol Suffers Data Theft and Ransomware Attempt
Ecopetrol, Colombia's state-controlled energy company, disclosed a cyberattack involving data theft from 3,300 user accounts and a ransomware attempt.
Jul 18, 2026No news matches your search.