Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe After Effects is a digital visual effects and motion...
Mozilla security advisory (AV26-692)
Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these...
56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the...
HPE security advisory (AV26-691)
Human did 10% of the job, AI did 90%
Michigan public health investigators say they are zeroing in on lettuce and other salad greens as potential sources of a massive outbreak of cyclosporiasis that has infected at least 2,640 people...
SAP security advisory – July 2026 monthly rollup (AV26-690)
Last month’s record-breaking heat wave killed thousands across Western Europe, making it one of the continent’s deadliest climate disasters. Preliminary official mortality data and researchers’...
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel.
Just two years ago, hackers were tapping into generative artificial intelligence to probe targets, translate technical material and troubleshoot malicious code. The technology sped up some key...
[Control systems] Siemens security advisory (AV26-689)
The Trump administration’s abrupt firing of Election Assistance Commission commissioners last week and a Department of Justice warning threatening states with criminal prosecution have created new...
OAuth client ID spoofing lets attackers test Entra accounts and stolen passwords without successful sign-ins, leaving application names blank in logs.
Global cyber attacks rose over 10% in June, according to new research from Check Point, with one particular group accounting for a growing portion. The uptick in attacks comes in the wake of what...
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious...
Cyberattack attempts against the South Korean military reached nearly 19,000 last year, marking the highest figure in five years, a lawmaker said Sunday. The military was targeted in 18,951...
This year, the U.S. military’s use of artificial intelligence (AI) in its targeting has burst into the spotlight. In February, the Wall Street Journal reported that the military used the Anthropic...
Department of Homeland Security personnel twice dismissed signs of cyber intruders inside the agency’s Homeland Security Information Network as harmless activity, allowing hackers to remain...
The UK and EU are demanding urgent action from critical infrastructure organizations after formally attributing the December 2025 cyberattack on Poland’s power grid to Russia’s Federal Security...
Flaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide
The Pentagon is suspending the ramp up of new Cybersecurity Maturity Model Certification third-party assessment requirements, while also launching a sweeping review of the CMMC program that once...
Gov. Kathy Hochul of New York is set to sign an executive order today placing a one-year pause on the construction of the largest data centers, putting the state at the forefront of the national...
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from...
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform....
FIFA’s network was vulnerable to anyone with even minimal access.
Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence...
Detect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack.
Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Infection through LNK...
This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation...