ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

Security Incidents

Aggregated security news from trusted sources

HackerNews 1 month ago

Wallabag Full Disclosure CVSS8.5 Stored XSS+SSRF after no patched no cve

Article URL: https://infosec.exchange/@FUNFACTOR1/117093620077858014 Comments URL: https://news.ycombinator.com/item?id=49301189 Points: 2 # Comments: 0

SecurityWeek 1 month ago

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disrupt...

SecurityWeek 1 month ago

Trivy, Not LiteLLM Behind the 2,500 Org Compromise

Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek.

SecurityWeek 1 month ago

Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal

Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness G...

SecurityWeek 1 month ago

1.6 Million Likely Impacted by RingCentral Data Breach

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers. The post 1.6 Million Likely Impacted by RingCentral Data Breach appeared first o...

SecurityWeek 1 month ago

Over 1,000 Charities Hit by Beacon CRM Data Breach

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts. The post Over 1,000 Charities Hit by Beacon CRM Data Br...

SecurityWeek 1 month ago

14,000 Trezor Customers Impacted by Data Breach at ShipMonk

Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers. The post 14,000 Trezor Customers Impacted by Data Breach at ShipMonk appeared first o...

HackerNews 1 month ago

You're Back in the Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

Article URL: https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ Comments URL: https://news.ycombinator.com/item?id=49295904 Points: 2 # Comments: 0

SecurityWeek 1 month ago

Hackers Exploiting Unpatched GeoServer Zero-Day

The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWee...

SecurityWeek 1 month ago

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser S...

SecurityWeek 1 month ago

Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 ap...

SecurityWeek 1 month ago

Adobe Commerce Bug Targeted Immediately After Disclosure

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on Securit...

The Hacker News 1 month ago

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS...

The Hacker News 1 month ago

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdo...

The Hacker News 1 month ago

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API ke...

The Hacker News 1 month ago

Enterprise Defenses Recovered at the Edge and Collapsed Inside

Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 33...

The Hacker News 1 month ago

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code exe...

HackerNews 1 month ago

A BSON symbol namespace bypasses MongoDB's authorization check (CVE-2026-18690)

Article URL: https://hellorecon.com/blog/cve-2026-18690-mongodb-symbol-type-authz-bypass Comments URL: https://news.ycombinator.com/item?id=49273886 Points: 9 # Comments: 0

The Hacker News 1 month ago

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-593...

The Hacker News 1 month ago

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other...