Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
White House Memo Opens Door for Private Offensive Cyber Operations
The White House published a presidential memorandum that creates a legal framework for engaging private cybersecurity companies to conduct offensive ...
How a Fake DeFi Startup Helped Unmask North Korean IT Operators
Specialists from BCA LTD, NorthScan and ANY.RUN carried out an operation in which they set up a fake DeFi startup ...
Critical Adobe ColdFusion, Commerce and Campaign Classic Bugs Fixed
Adobe has released security updates that address seven critical vulnerabilities in ColdFusion, Adobe Commerce and Adobe Campaign Classic. Three of ...
SAP Fixes Critical Commerce Cloud RCE and MII Flaws
As part of its August security update, SAP fixed four critical vulnerabilities, the most severe of which — CVE-2026-58231 in ...
ShieldBreak and August 2026 Patch Tuesday: Risks and Guidance
Security researcher operating under the alias Chaotic Eclipse has published a PoC exploit named ShieldBreak, which he claims completely bypasses ...
Exploitation of Cisco ASA and FTD VPN vulnerability CVE-2026-20349
Cisco has confirmed active exploitation of vulnerability CVE-2026-20349 (CVSS 8.6) in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall ...
August 2026 Microsoft Patch Tuesday: Priority Guidance for CVE-2026-68820
Microsoft’s August security update addresses CVE-2026-68820 — a privilege escalation vulnerability in the Windows kernel driver afd.sys that, according to ...
How OpenAI’s GPT-5.6-Cyber Changes Cyber Defense
OpenAI has introduced the specialized model GPT-5.6-Cyber, designed for zero-day vulnerability discovery, exploit chain development, and incident response. The model ...
How CVE-2026-55040 Lets Attackers Hijack On‑Prem SharePoint
The CVE-2026-55040 vulnerability (CVSS 9.1) in the JSON Web Token validation pipeline on Microsoft SharePoint servers allows a remote unauthenticated ...
Why Mozilla Revoked Its Firefox and Thunderbird Linux Signing Key
Mozilla has revoked the cryptographic subkey (subkey) used to sign Firefox and Thunderbird downloads for Linux, after an unencrypted copy ...