Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Dependency-Confusion Attack Delivers RAT via Fake Alibaba npm Packages
Researchers at Socket have discovered 18 malicious npm packages targeting developers who use tools from the Alibaba Group ecosystem. The ...
Unit 42 details three post-exploit attacks on Chrome passkeys
Researchers from Palo Alto Networks Unit 42 have published a study of three post-exploitation techniques that allow malware running with ...
Coldcard firmware flaw leaves Bitcoin seeds under-protected
Researchers at Block have disclosed a critical bug in the firmware of Coldcard hardware wallets made by Canadian company Coinkite: ...
In-depth look at Cisco Secure FMC CVE-2026-20316 and its exploitation chain
On July 29, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added vulnerability CVE-2026-20316 to the Known Exploited Vulnerabilities ...
Urgent Updates for Adobe Campaign Classic and Bridge
Adobe has released security updates that address the maximum‑severity vulnerability CVE-2026-48449 (CVSS 10.0) in the marketing automation platform Adobe Campaign ...
How the Fairlife Ransomware Attack Hit Coca-Cola’s Operations
Coca-Cola has officially confirmed that the ransomware attack on its dairy subsidiary Fairlife involved unauthorized access to systems and data ...
CVE-2026-33825 BlueHammer: Windows LPE Exploit and Researcher–Microsoft Conflict
The local privilege escalation vulnerability CVE-2026-33825 affecting Microsoft Windows has become the starting point of a public conflict between a ...
CVE-2026-10702: Public Exploit and Firefox 151.0.3 Patch
Mozilla has released an emergency update Firefox 151.0.3 that fixes the high-severity vulnerability CVE-2026-10702 in the browser’s JIT compiler. The ...
How CVE-2026-60004 Exposes Gitea and Why You Must Upgrade
Gitea has fixed a critical remote code execution vulnerability (CVE-2026-60004, CVSS 9.8) that allows a user with write access to ...
CVE-2013-4786: IPMI Password Hash Exposure Puts BMCs at Risk
According to researchers at Lava, more than 36,000 Baseboard Management Controllers (BMC) using the IPMI protocol are reachable from the ...