-
ASUS has released a security update for the Control Center Express Agent to address CVE-2026-19397, a high-severity vulnerability related to missing authentication. This vulnerability allows an unauthenticated nearby attacker to potentially take contro…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SAP released 19 new Security Notes addressing four critical vulnerabilities and 15 additional flaws throughout its enterprise portfolio. The vendor also updated one note from August. The most urgent issue is CVE-2026-44756, a memory-corruption vulnerab…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Department of State’s Rewards for Justice (RFJ) program has announced a reward of up to $10 million for information leading to the identification or location of Amir Yaryab, a senior official in Iran’s Islamic Revolutionary Guard Corps Cyber-E…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have demonstrated how vulnerabilities in AI-powered customer service agents can be exploited to bypass identity checks, expose sensitive customer data, exfiltrate one-time passwords (OTPs), and trigger unauthorized account actions….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly documented ransomware intrusion attributed to The Gentlemen shows how attackers can convert a foothold in a Windows environment into domain-wide control by elevating accounts, turning off endpoint defenses, and abusing trusted Active Directory …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s ra…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Coder has reported a significant software supply chain incident in which an unidentified threat actor redirected part of its official module registry traffic to attacker-controlled infrastructure. This led to the temporary distribution of tampered Terr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed BigBear 2.0 to intercept authenticated Microsoft 365 sessions, allowing them to take over accounts even after victims complete multi-factor authentication (MFA). Cloud…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A known Shai-Hulud npm worm payload has resurfaced after 111 days of inactivity, raising fresh questions about the effectiveness of registry-level malware screening. The May campaign demonstrated how quickly a single compromised maintainer account can …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Switzerland’s Federal Chancellery is advancing a sovereign digital workplace initiative following a feasibility study that demonstrated how open-source collaboration and office software can effectively support essential workflows within the federal adm…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


