Enterprise Java Vulnerabilities Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz
Security research presented at Black Hat 2026 has identified 12 vulnerabilities across four enterprise Java platforms, including two critical pre-authenticat...
20 articles
Security research presented at Black Hat 2026 has identified 12 vulnerabilities across four enterprise Java platforms, including two critical pre-authenticat...
A cyber security risk assessment is a structured process for identifying, analyzing, and prioritizing the risks to an organization’s information systems, dat...
Security researchers have demonstrated an indirect prompt-injection chain affecting Claude in Chrome that can transform a standard request, such as summarizi...
A Google dork is an advanced search query that combines Google’s search operators (such as site:, intitle:, inurl:, and filetype:) to surface information tha...
Security researchers have shown how attackers could exploit Microsoft Windows Server Update Services (WSUS) infrastructure to distribute malicious software u...
Security researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an ...
A coordinated cyber campaign targeting internet-facing programmable logic controllers (PLCs) has disrupted water and wastewater operations across the United ...
In the sprawling digital ecosystem of 2026, organizations grapple with an increasingly complex and often poorly understood external attack surface. This atta...
In today’s interconnected digital world, no organization is truly safe from cyber threats. A single unpatched vulnerability can become an open door for a dev...
The firewall policy management market had its earthquake: Skybox Security shut down overnight in February 2025, selling its technology to Tufin and leaving c...
Protective DNS is the rare control where the cheap options are genuinely good so this comparison leads with value.
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed servers o...
The fake “undetected” Xeno Roblox executor currently circulating on gaming forums and Discord is a weaponized loader for the Powercat Java stealer, a multi‑s...
Cloudflare has open-sourced Cloudflare OS, a platform designed to provide enterprise AI agents with controlled access to internal systems, company context, a...
Vanta Stealer is a Python‑based, cross‑platform information stealer that uses layered PyArmor obfuscation on top of a PyInstaller‑packed executable to harves...
KHunt shows how a “routine” SQL injection against an Oracle‑backed web app can be weaponized into SYSTEM‑level remote code execution and credential theft by ...
Meta has become the latest technology company to disclose that an AI agent accessed another organization’s online systems during a controlled cybersecurity e...
A critical vulnerability in Jenkins, tracked as CVE-2026-70426, may allow attackers to execute arbitrary code on Jenkins controllers by bypassing deserializa...
A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel’s software bridge implementation found in `net/bridg...
OpenAI has revealed new details about an incident involving AI agents, in which multiple autonomous agents reportedly worked together to identify vulnerabili...