No one knows how many old shims can still bypass UEFI Secure BootHelp Net Security·Jul 14, 00:00 UTC · Jul 14, 2026VulnerabilityCVE-2026-8863CVE-2026-10797CVE-2015-528135
Why shorter SSL/TLS certificate lifespans matterHelp Net Security·Apr 15, 00:00 UTC · Apr 15, 2025Vulnerability30
Why app modernization can leave you less secureHelp Net Security·May 27, 00:00 UTC · May 27, 2025Vulnerability55
Trump orders revocation of security clearances for Chris Krebs, SentinelOneHelp Net Security·Apr 17, 13:57 UTC · Apr 17, 2025Vulnerability30
BlackLotus UEFI bootkit disables Windows security mechanismsHelp Net Security·Apr 17, 10:14 UTC · Apr 17, 2023Vulnerability in the wildCVE-2022-2189460
Microsoft’s Secure Boot has been broken for a decade and no one noticed until nowArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2015-5381160
Deleted Google API keys keep working for up to 23 minutes, researchers warnHelp Net Security·May 22, 00:00 UTC · May 22, 2026Vulnerability30
Leveraging Credentials As Unique Identifiers: A Pragmatic Approach To NHI InventoriesThe Hacker News·Jun 30, 11:00 UTC · Jun 30, 2025Vulnerability30
Rethinking governance in a decentralized identity worldHelp Net Security·Jun 4, 00:00 UTC · Jun 4, 2025Vulnerability55
Microsoft's May Patch Tuesday Fixes 38 Flaws, Including 2 Exploited ZeroThe Hacker News·May 15, 00:00 UTC · May 15, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-29325CVE-2023-24932+1 CVEs60
Eleven Vulnerable UEFI Shims Enable Secure Boot BypassInfosecurity Magazine·Jul 15, 14:00 UTC · Jul 15, 2026VulnerabilityCVE-2026-8863CVE-2026-10797135
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure BootThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026VulnerabilityCVE-2026-8863CVE-2026-1079747
Debian 13.6 security update patches over a hundred advisories in trixieHelp Net Security·Jul 13, 00:00 UTC · Jul 13, 2026Vulnerability130
AI coding agents keep repeating decade-old security mistakesHelp Net Security·Jun 19, 12:07 UTC · Jun 19, 2026Vulnerability42
Connectwise is rotating code signing certificates. What happened?Help Net Security·Jun 11, 00:00 UTC · Jun 11, 2025Vulnerability30
The shocking speed of AWS key exploitationHelp Net Security·Dec 2, 00:00 UTC · Dec 2, 2024Vulnerability130
Microsoft fixes two actively exploited bugs, one used by BlackLotus bootkit (CVE-2023-29336, CVE-2023-24932)Help Net Security·May 9, 00:00 UTC · May 9, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2022-21882+10 CVEs160
Enterprises leaving themselves vulnerable to cyberattacks by failing to prioritize PKI securityHelp Net Security·Oct 4, 00:00 UTC · Oct 4, 2019Vulnerability55
New WordPress Pre-Auth XSS Could Lead to PHP Code ExecutionThe Hacker News·Aug 8, 08:07 UTC · Aug 8, 2026Vulnerability in the wildCVE-2026-64638160
ServiceNow organizes autonomous security around six solution areasHelp Net Security·Aug 4, 00:00 UTC · Aug 4, 2026Vulnerability55
OAuth marketplace apps keep access after publishers vanishHelp Net Security·Jul 1, 03:09 UTC · Jul 1, 2026Vulnerability142
Hundreds of AI-powered iOS apps found exposing credentialsHelp Net Security·Jun 22, 00:00 UTC · Jun 22, 2026Vulnerability30
Machine identities outnumber humans 109 to 1Help Net Security·May 14, 00:00 UTC · May 14, 2026Vulnerability30
Composer vulnerability leaks GitHub tokens, threatens PHP supply chainSansec (Magento / e-commerce security)·May 13, 14:54 UTC · May 13, 2026Vulnerability155
Day Zero Readiness: The Operational Gaps That Break Incident ResponseThe Hacker News·May 7, 10:54 UTC · May 7, 2026Vulnerability55
As AI agents start making purchases, security teams must rethink riskHelp Net Security·Mar 5, 00:00 UTC · Mar 5, 2026Vulnerability55
Week in review: Fully patched FortiGate firewalls are getting compromised, attackers probe Cisco RCE flawHelp Net Security·Jan 25, 00:00 UTC · Jan 25, 2026VulnerabilityCVE-2026-20045CVE-2025-5971860
Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin ServersThe Hacker News·Jan 20, 11:12 UTC · Jan 20, 2026Vulnerability30
Attackers target retailers’ gift card systems using cloud-only techniquesHelp Net Security·Oct 22, 00:00 UTC · Oct 22, 2025Vulnerability30
Sophos ITDR enhances identity security with dark web monitoring and automated responseHelp Net Security·Oct 21, 00:00 UTC · Oct 21, 2025Vulnerability30
Google: Salesloft Drift breach hits all integrationsSecurity Affairs·Aug 29, 09:14 UTC · Aug 29, 2025Vulnerability30
The Persistence Problem: Why Exposed Credentials Remain Unfixed—and How to Change ThatThe Hacker News·May 12, 11:00 UTC · May 12, 2025Vulnerability55
Week in review: Microsoft patches exploited Windows CLFS 0-day, WinRAR MotW bypass flaw fixedHelp Net Security·Apr 13, 00:00 UTC · Apr 13, 2025Vulnerability in the wildCVE-2025-29824CVE-2025-31334CVE-2024-48887+2 CVEs160
New UEFI Secure Boot bypass vulnerability discovered (CVE-2024-7344)Help Net Security·Jan 16, 00:00 UTC · Jan 16, 2025VulnerabilityCVE-2024-734435
New UEFI Secure Boot Vulnerability Could Allow Attackers to Load Malicious BootkitsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025VulnerabilityCVE-2024-734435
Users of JetBrains IDEs at risk of GitHub access token compromise (CVE-2024-37051)Help Net Security·Jun 11, 00:00 UTC · Jun 11, 2024Vulnerability in the wildCVE-2024-3705160
AppViewX AVX ONE provides visibility, automation and control of certificates and keysHelp Net Security·May 8, 00:00 UTC · May 8, 2024Vulnerability55
Microsoft Fixes 149 Flaws in Huge April Patch Release, ZeroThe Hacker News·Apr 11, 11:08 UTC · Apr 11, 2024Vulnerability in the wildCVE-2024-26234CVE-2024-29988CVE-2024-21412+2 CVEs60