OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised
Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a se...
20 articles
Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a se...
The phishing campaigns that weaponize legitimate remote monitoring and management software to establish persistent access and support credential theft on Win...
A Pentagon personnel database was breached for nine months without anyone noticing. Over three million people are affected.
In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI. The post ShinyHunters Defiant After FBI ...
Internet-exposed tech, PLCs, outside integrators and inside protections are all factors the water sector’s information sharing and analysis center is watchin...
Threat actors are actively exploiting a critical zero-day vulnerability in Citrix NetScaler, identified as CVE-2026-88772, to gain unauthenticated root-level...
RSA has launched RSA Agent ID, an identity security platform that discovers, secures, and governs AI agents and Model Context Protocol (MCP) servers in highl...
Threat actors exploited a chained pair of PaperCut MF zero-day vulnerabilities to compromise an education-sector environment, steal a domain-privileged servi...
Signal users who switch from an Android phone to an iPhone, or the other way around, can take their message history with them, and backups can be restored on...
Threat actors abused fake ChatGPT Custom GPTs and ClickFix to deliver a multi-stage RAT. ChatGPT’s Custom GPT feature is the latest legitimate surface being ...
Compare 8 top red teaming providers for enterprise adversary emulation, from DeepSeas and Mandiant to CrowdStrike, IBM, SpecterOps, TrustedSec and NCC Group.
Apple has patched CVE-2026-86950, a zero-day bug in the iOS CoreGraphics engine
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organiza...
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fi...
OperTraitor, an open-source, LLM-powered engine that identifies Kubernetes operators whose RBAC (Role-Based Access Control) privileges exceed their documente...
U.S.
A high-severity Linux kernel vulnerability, tracked as CVE-2026-72018, lets a local attacker with CAP_NET_ADMIN privileges escalate to root. This exploitatio...
Two men who ran BEC and phishing campaigns against US businesses while serving in the Air Force have been sentenced to a combined 189 months in federal priso...
Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and ...