Atlassian Rovo prompt injection can send Jira and Confluence data to attacker servers. One path is fixed; another remained ...
Outlook CSS techniques can spoof Microsoft sign-in and capture passwords, while Gmail image-set() can trigger external ...
CISA adds Progress Kemp LoadMaster CVE-2026-8037 to KEV after active exploitation reports, with 792 attempts logged across 65 ...
Oligo links TeamPCP activity back to Redis attacks in 2020, tracing its shift from cloud exploitation to open-source supply ...
Open source may split as the EU Cyber Resilience Act and enterprise security demands favor reachable, patchable, accountable ...
AitM phishing hijacks Microsoft 365 accounts, then uses residential proxies and Microsoft Graph API access to collect payroll ...
UNC6671 uses vishing and AitM phishing to steal cloud credentials and MFA tokens, then exfiltrate data from Microsoft 365, ...
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under ...
NatJack abuses NAT state to hijack TCP sessions and spoof DNS responses; Windows and Linux flaws are tracked under two CVEs.
Metabase says a CVSS 10.0 zero-day SQL injection was exploited in the wild; the flaw can grant admin access and expose ...
N-able releases N-central Hotfix 2 amid CVE-2026-18577 exploitation that gave attackers admin access and persistent access to managed systems.
ClickFix attacks deliver a Go-based macOS stealer that steals passwords and Keychain data and can drain part or all of ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results