ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

Security Incidents

Aggregated security news from trusted sources

The Hacker News 1 month ago

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE ide...

The Hacker News 1 month ago

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldB...

The Hacker News 1 month ago

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The hi...

HackerNews 1 month ago

CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape

Article URL: https://github.com/sgkdev/bad_garbage Comments URL: https://news.ycombinator.com/item?id=49267550 Points: 13 # Comments: 0

The Hacker News 1 month ago

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket o...

The Hacker News 1 month ago

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience...

The Hacker News 1 month ago

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, th...

The Hacker News 1 month ago

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the coun...

The Hacker News 1 month ago

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an...

The Hacker News 1 month ago

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "I...

The Hacker News 1 month ago

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol,...

The Hacker News 1 month ago

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics un...

The Hacker News 1 month ago

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was record...

The Hacker News 1 month ago

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these...

HackerNews 1 month ago

Expat 2.8.3 released, fixes vulnerability CVE-2026-72522

Article URL: https://blog.hartwork.org/posts/expat-2-8-3-released/ Comments URL: https://news.ycombinator.com/item?id=49257903 Points: 1 # Comments: 0

The Hacker News 1 month ago

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reac...

The Hacker News 1 month ago

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily dis...

HackerNews 1 month ago

CVE-2026-56852: x/text/Unicode/norm infinite loop on invalid UTF-8 (DoS)

Article URL: https://pkg.go.dev/vuln/GO-2026-5970 Comments URL: https://news.ycombinator.com/item?id=49256278 Points: 2 # Comments: 0

The Hacker News 1 month ago

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. Whe...

The Hacker News 1 month ago

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncrypto...