Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
HashiCorp, Veeam and Django patch 11 new CVEs in 2026
HashiCorp, Veeam and the Django Software Foundation released fixes in early August 2026 for 11 vulnerabilities, three of which are ...
Active Exploitation of CVE-2026-63077 in JetBrains TeamCity Confirmed by CISA
CISA on August 5, 2026 added the vulnerability CVE-2026-63077 to the Known Exploited Vulnerabilities (KEV) catalog, confirming its active exploitation. ...
CISA flags Langflow, Tomcat and N-central bugs under active attack
CISA has added three vulnerabilities with confirmed active exploitation to the Known Exploited Vulnerabilities (KEV) catalog: a critical RCE in ...
Active Exploitation of N-able N-central Authentication Flaws
N-able has confirmed active exploitation of critical authentication bypass vulnerabilities in the N-central platform — a remote monitoring and management ...
Keyv npm ecosystem compromise: worm-like spread through stolen tokens
On August 4, 2026, a large-scale supply chain attack was recorded in the npm ecosystem: malicious code first discovered in ...
N-able N-central CVE-2026-18577 Auth Bypass Added to CISA KEV
CVE-2026-18577 is an authentication bypass vulnerability in the N-able N-central remote monitoring platform (CVSS 8.2). It was added by CISA ...
Dependency-Confusion Attack Delivers RAT via Fake Alibaba npm Packages
Researchers at Socket have discovered 18 malicious npm packages targeting developers who use tools from the Alibaba Group ecosystem. The ...
Unit 42 details three post-exploit attacks on Chrome passkeys
Researchers from Palo Alto Networks Unit 42 have published a study of three post-exploitation techniques that allow malware running with ...
Coldcard firmware flaw leaves Bitcoin seeds under-protected
Researchers at Block have disclosed a critical bug in the firmware of Coldcard hardware wallets made by Canadian company Coinkite: ...
In-depth look at Cisco Secure FMC CVE-2026-20316 and its exploitation chain
On July 29, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added vulnerability CVE-2026-20316 to the Known Exploited Vulnerabilities ...