Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
500 stories published
Six U-Boot Signature Verification Flaws Expose Embedded Devices to Stealthy Firmware…
Binarly researchers disclosed six vulnerabilities in the U-Boot bootloader, including arbitrary code execution flaws that could enable stealthy firmware…
Jul 11, 2026Django GeoDjango SQL Injection (CVE-2026-1207) Under Active Exploitation
A high-severity SQL injection vulnerability (CVE-2026-1207) in Django's GeoDjango GIS module is now actively exploited, affecting applications with a PostGIS…
Jul 11, 2026Oracle PeopleSoft Zero-Day (CVE-2026-35273) Actively Exploited, NAIC Affected
A new zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft is under active exploitation, affecting approximately 100 organizations, including NAIC.
Jul 11, 2026Nitrogen Ransomware Group Targets Foxconn North America, Exfiltrates 8TB of Data
The Nitrogen ransomware group claims to have stolen 8 terabytes of sensitive engineering documents and client schematics from Foxconn's North America…
Jul 11, 2026Medtronic Notifies Millions of Individuals Impacted by ShinyHunters Data Breach
Medical device giant Medtronic confirms a data breach impacting nearly 4 million individuals, with personal and health information exposed.
Jul 11, 2026AI Agents Exploit Langflow RCE Vulnerability for Automated Database Ransomware Attacks
An AI agent has been observed exploiting a Remote Code Execution (RCE) vulnerability in Langflow to automate database ransomware attacks, highlighting…
Jul 10, 2026Microsoft Patches RoguePlanet (CVE-2026-50656) Local Privilege Escalation in Defender
Microsoft has released a security update to address CVE-2026-50656, a local privilege escalation vulnerability dubbed 'RoguePlanet' in its Malware Protection…
Jul 10, 2026GodDamn Ransomware Uses Signed PoisonX Kernel Driver to Disable EDR Defenses
A new ransomware variant, GodDamn, a rebrand of Beast ransomware, employs the legitimately signed PoisonX kernel driver to bypass and neutralize endpoint…
Jul 10, 2026Unpatched XRING Flaw in Alibaba's XQUIC Allows Remote HTTP/3 Server Crashes
A critical and unpatched vulnerability, named XRING, in Alibaba's XQUIC library enables remote denial-of-service against HTTP/3 servers.
Jul 10, 2026Ill Bloom Vulnerability Compromises Crypto Wallets Through Weak Randomness
A newly disclosed vulnerability, dubbed "Ill Bloom," in certain crypto wallet software allows attackers to drain funds due to weak recovery phrase generation.
Jul 10, 2026Cisco Talos Discloses Multiple Vulnerabilities in WolfSSL, GeoVision, and VTK-DICOM
Cisco Talos has identified and reported numerous vulnerabilities in WolfSSL, GeoVision security products, and the VTK-DICOM API.
Jul 10, 2026Nextcloud Hosting Misconfiguration Exposes Sensitive Employee and Client Data
A misconfiguration in a Nextcloud hosting environment led to the exposure of sensitive employee emails, client details, contracts, and scripts.
Jul 10, 2026No news matches your search.