Critical Splunk Auth Bypass Flaw CVE-2026-20253 Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency...
HazyBeacon Malware Hijacks AWS Lambda for Covert C2 Attacks
A sophisticated cloud-native malware campaign, tracked...
CVE-2026-50656: RoguePlanet Zero-Day Bypasses Microsoft Defender
Microsoft has officially confirmed a newly disclosed...
Splunk AI Toolkit Flaw Lets Admins Run Arbitrary OS Commands
Splunk has disclosed a critical security vulnerability in...
CVE-2026-4020: Gravity SMTP Flaw Exposes 100K WordPress Sites
Threat actors are actively exploiting a critical security...
Critical Joomla Plugin Flaw Allows Unauthenticated PHP Code Execution
A critical improper access control vulnerability has been...
OpenBSD PAP Auth Bypass Flaw Lurked Undetected for 27 Years
A critical authentication-bypass vulnerability hiding in...
CISA Adds Oracle PeopleSoft CVE-2026-35273 to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency...
UNC3753 Targets U.S. Law Firms With Hybrid Extortion Attacks
A financially motivated threat actor tracked as UNC3753,...
ShinyHunters Breaches Infinite Campus, Leaks 137,000 User Records
The popular K-12 student information system Infinite Campus...