Operation Phantom Thread: Supply chain attack targets GitHub Action runners to steal secrets
A highly targeted supply chain campaign has been identified that compromises the software build process by poisoning third-party Actions within […]
A highly targeted supply chain campaign has been identified that compromises the software build process by poisoning third-party Actions within […]
A high-severity remote code execution vulnerability in a mobile device management platform has been added to the federal list of
CISA adds Ivanti EPMM RCE vulnerability to KEV catalog following targeted abuse Read More »
Official security updates have been released to address a critical root-level vulnerability in the perimeter security infrastructure of several thousand
Palo Alto Networks releases emergency patches for PAN-OS root-level zero-day RCE Read More »
A critical authentication bypass vulnerability in Linux-based web hosting control panels is being mass-exploited to deploy a new strain of
The parent company of a global learning management system has confirmed reaching a settlement with threat actors to avoid the
Instructure pays ransom to ShinyHunters to prevent 3.65TB Canvas LMS data leak Read More »
Enterprise security teams are entering the final 24 hours of a critical unpatched exposure period for perimeter firewalls. Official software
Palo Alto Networks prepares for May 13 patch rollout for critical PAN-OS zero-day Read More »
Cybersecurity researchers have identified a sophisticated zero-day exploit that appears to have been developed with the assistance of an advanced
Google identifies first AI-generated zero-day exploit targeting web admin tools Read More »
A malicious repository masquerading as a legitimate privacy tool from a leading AI laboratory trended on Hugging Face, leading to
Typosquatted OpenAI Privacy Filter repo on Hugging Face delivers Rust-based infostealer Read More »
A critical heap out-of-bounds read vulnerability has been disclosed in a popular open-source framework used for running large language models
Critical Bleeding Llama vulnerability in Ollama allows remote process memory leak Read More »
A critical improper input validation vulnerability in the Ivanti Endpoint Manager Mobile platform has been added to the federal list
Ivanti EPMM zero-day CVE-2026-6973 added to CISA KEV following targeted attacks Read More »