Critical Adobe Commerce Flaw Lets Unauthenticated Attackers Escalate Privileges
Adobe has released security updates for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source to address multiple critical vulnerabilities. One of the ...
20 articles
Adobe has released security updates for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source to address multiple critical vulnerabilities. One of the ...
The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach
WhatsApp has initiated a limited beta rollout of a feature called Scam Alert, which utilises an on-device machine learning model to identify potentially scam...
Adobe has released critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing 17 vulnerabilities that could enable arbitrary code executio...
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, ...
An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-ED...
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has con...
Gunra ransomware has added a Linux encryptor to its arsenal, giving affiliates control over how they lock enterprise data. The command-line payload can launc...
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Po...
A newly identified Kimwolf v7 build shows the Android and IoT botnet shifting from an all-in-one compromise toolkit into a more specialized DDoS and proxy-re...
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerab...
A China-linked threat actor has reportedly utilized a multi-agent artificial intelligence framework to conduct a nearly autonomous intrusion campaign targeti...
Phantom Stealer is a .NET-based credential-harvesting malware that combines PNG-backed payload concealment, PowerShell-driven process injection, and telemetr...
A sophisticated threat campaign, referred to as “City-Forum,” is targeting publicly accessible Salesforce Experience Cloud sites and ServiceNow Service Porta...
Palo Alto Networks has released security advisories for multiple vulnerabilities in the GlobalProtect App that could allow a local attacker to elevate their ...
WordPress has released version 7.0.
In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the for...
DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Clo...
Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by ...
Wireshark 4.6.