Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992)Help Net Security·Mar 23, 00:00 UTC · Mar 23, 2026Vulnerability in the wildCVE-2026-21992CVE-2025-6175760
Oracle fixes critical RCE flaw CVE-2026Security Affairs·Mar 22, 15:37 UTC · Mar 22, 2026Vulnerability in the wildCVE-2026-21992CVE-2025-6175760
Docker Fixes Critical Ask Gordon AI Flaw Allowing Code Execution via Image MetadataThe Hacker News·Feb 3, 16:41 UTC · Feb 3, 2026Vulnerability155
Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin AccessThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC in the wildCVE-2026-2355060
Maximum Severity “Ni8mare” Bug Lets Hackers Hijack n8n ServersInfosecurity Magazine·Jan 8, 10:00 UTC · Jan 8, 2026RansomwareCVE-2026-2185860
LLMs are everywhere in your stack and every layer brings new riskHelp Net Security·Dec 10, 00:00 UTC · Dec 10, 2025Vulnerability42
Critical Infrastructure Protection: The Role of Attack Surface IntelligenceRecorded Future·Nov 28, 00:00 UTC · Nov 28, 2025Ransomware60
CISA Urges Patch of Actively Exploited Flaw in Oracle Identity ManagerInfosecurity Magazine·Nov 24, 11:07 UTC · Nov 24, 2025Vulnerability in the wildCVE-2025-61757CVE-2021-3558760
CISA Warns of Actively Exploited Critical Oracle Identity Manager ZeroThe Hacker News·Nov 22, 14:50 UTC · Nov 22, 2025Advisory in the wildCVE-2025-6175760
ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware WavesThe Hacker News·Nov 21, 06:45 UTC · Nov 21, 2025MalwareCVE-2025-61757CVE-2025-1124360
Preparing for the Digital Battlefield of 2026: Ghost Identities, Poisoned Accounts, & AI Agent HavocThe Hacker News·Oct 29, 11:55 UTC · Oct 29, 2025Vulnerability55
Critical Vulnerability in Salesforce AgentForce ExposedInfosecurity Magazine·Sep 25, 17:00 UTC · Sep 25, 2025Vulnerability55
A Cyberattack Victim Notification FrameworkSchneier on Security·Sep 12, 21:04 UTC · Sep 12, 2025Phishing & fraud30
Axios User Agent Helps Automate Phishing on “Unprecedented Scale”Infosecurity Magazine·Sep 9, 13:00 UTC · Sep 9, 2025Phishing & fraud30
Hackers deploy DripDropper via Apache ActiveMQ flaw, patch systems to evade detectionSecurity Affairs·Aug 21, 16:30 UTC · Aug 21, 2025Vulnerability in the wildCVE-2023-4660460
The AI security crisis no one is preparing forHelp Net Security·Aug 20, 00:00 UTC · Aug 20, 2025Vulnerability55
Gold Melody IAB Exploits Exposed ASP.NET Machine Keys for Unauthorized Access to TargetsThe Hacker News·Jul 11, 04:04 UTC · Jul 11, 2025Vulnerability55
Why data provenance must anchor every CISO’s AI governance strategyHelp Net Security·May 28, 00:00 UTC · May 28, 2025AI policy30
Why app modernization can leave you less secureHelp Net Security·May 27, 00:00 UTC · May 27, 2025Vulnerability55
AI hallucinations and their risk to cybersecurity operationsHelp Net Security·May 19, 00:00 UTC · May 19, 2025Vulnerability55
SAP cyberattack widens, drawing Salt Typhoon and Volt Typhoon comparisonsCyberScoop·May 15, 17:45 UTC · May 15, 2025Threat actor in the wild60
⚡ Weekly Recap: VPN Exploits, Oracle's Silent Breach, ClickFix Surge and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025Data breachCVE-2025-22457CVE-2025-24061CVE-2025-2407+15 CVEs60
Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby ServersThe Hacker News·Apr 25, 10:29 UTC · Apr 25, 2025Data breachCVE-2025-27610CVE-2025-27111CVE-2025-25184+1 CVEs160
Oracle confirms the hack of two obsolete servers hacked. No Oracle Cloud systems or customer data were affectedSecurity Affairs·Apr 10, 09:40 UTC · Apr 10, 2025Data breach60
Oracle privately notifies Cloud data breach to customersSecurity Affairs·Apr 6, 20:33 UTC · Apr 6, 2025Data breach60
Oracle To Address 320 Vulnerabilities in January Patch UpdateInfosecurity Magazine·Jan 21, 12:45 UTC · Jan 21, 2025Vulnerability in the wildCVE-2020-288360
Google Is Allowing Device FingerprintingSchneier on Security·Jan 12, 15:08 UTC · Jan 12, 2025Policy & legal30
Combatting the Evolving SaaS Kill Chain: How to Stay Ahead of Threat ActorsThe Hacker News·Jun 28, 15:42 UTC · Jun 28, 2024Threat actor57
Critical RCE Vulnerability Discovered in Ollama AI Infrastructure ToolThe Hacker News·Jun 25, 03:22 UTC · Jun 25, 2024VulnerabilityCVE-2024-37032CVE-2024-2247660
Oracle WebLogic Server OS Command Injection Flaw Under Active AttackThe Hacker News·Jun 4, 08:27 UTC · Jun 4, 2024Exploit / PoC in the wildCVE-2017-3506CVE-2023-2183960
CISA adds Oracle WebLogic Server flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 3, 18:29 UTC · Jun 3, 2024Exploit / PoC in the wildCVE-2017-350660
4 Instructive Postmortems on Data Downtime and LossThe Hacker News·Mar 1, 13:45 UTC · Mar 1, 2024Industry30
Why we need to secure IoT connections sooner rather than laterHelp Net Security·Jan 23, 13:28 UTC · Jan 23, 2024Vulnerability55
Threat actors exploit Apache ActiveMQ flaw to deliver the Godzilla Web ShellSecurity Affairs·Jan 22, 11:19 UTC · Jan 22, 2024Threat actor in the wildCVE-2023-4660460
Review: Engineering-grade OT security: A manager's guideHelp Net Security·Jan 8, 00:00 UTC · Jan 8, 2024Ransomware60
8220 gang exploits old Oracle WebLogic vulnerability to deliver infostealers, cryptominersHelp Net Security·Dec 20, 00:00 UTC · Dec 20, 2023VulnerabilityCVE-2020-14883CVE-2017-3506CVE-2020-1488260
Transcend enhances its privacy platform to address current and future compliance challengesHelp Net Security·Dec 15, 00:00 UTC · Dec 15, 2023Tools30
Galaxy Note 10 enhanced with DEVGURU's Connectivity StackHelp Net Security·Dec 14, 11:49 UTC · Dec 14, 2023AI tools & infra30
Flaw in Apache ActiveMQ Exposes Linux Systems to Kinsing MalwareInfosecurity Magazine·Nov 22, 17:00 UTC · Nov 22, 2023Malware in the wildCVE-2023-46604CVE-2023-491160