Category: Exploits
Accenture Confirms Breach After Hacker Lists 35 GB of Stolen Data
A threat actor known as '888' claims to have exfiltrated 35 GB of source code, credentials, and configuration files from Accenture, and…
Max-Severity Adobe ColdFusion Flaw Exploited Within Hours of Disclosure
A critical remote code execution vulnerability in Adobe ColdFusion is under active attack, with exploitation observed less than two hours after Adobe…
Japanese Teen Arrested for Cyberattack That Canceled 46,000 Anime Subscriptions
A 15-year-old near Tokyo allegedly exploited a server vulnerability in Bandai Channel, using a ChatGPT-assisted tool to mass-cancel user accounts and force…
Medtronic Notifies 3.8 Million Patients After ShinyHunters-Linked Breach
The world's largest medical device maker has begun notifying nearly 4 million people that hackers accessed sensitive personal and health-related data from…
Google Project Zero Chains Pixel 9 Sandbox Escape via BigWave Kernel Driver
A Project Zero researcher found three bugs in the Pixel 9's BigWave AV1 hardware driver, one of which enables a full mediacodec…
Google and FBI Dismantle NetNut Botnet Spanning Millions of Android Devices
A coordinated operation involving Google, the FBI, and industry partners has significantly degraded NetNut, a residential proxy network built on more than…
Medtronic Data Breach Exposes 3.8 Million Patients via ShinyHunters Attack
Medical device maker Medtronic is notifying nearly 3.84 million individuals after the ShinyHunters extortion group accessed corporate IT systems in April 2026,…
Progress Kemp LoadMaster Pre-Auth RCE Flaw Under Active Exploitation
A critical OS command injection vulnerability in Progress Kemp LoadMaster is being actively targeted, with exploitation attempts identified by eSentire's Threat Response…
Password-Spraying Campaign Hits Microsoft 365 with 81M Login Attempts
A two-week campaign exploiting the ROPC OAuth flow bypassed MFA controls across dozens of organizations, compromising 78 Microsoft 365 accounts at 64…
SEO-Poisoned Sites Abuse ScreenConnect to Drop AsyncRAT
Kaspersky has identified a large-scale campaign using fake software download sites and ScreenConnect to deliver the AsyncRAT remote access trojan to unsuspecting…
Cisco Confirms Active Exploitation of Unified CM SSRF Flaw
Cisco has formally acknowledged that attackers are actively exploiting CVE-2026-20230, a server-side request forgery vulnerability in Unified Communications Manager patched in early…
CitrixBleed-Style NetScaler Flaw Exploited Within 24 Hours of Disclosure
A newly disclosed memory-disclosure vulnerability in NetScaler ADC and Gateway drew active exploitation attempts less than a day after Citrix released patches…