Category: Vulnerabilities
Trezor Discloses Data Breach at Shipping Partner ShipMonk, 14,000 Customers Affected
A breach at third-party fulfillment provider ShipMonk exposed names, addresses, and contact details of nearly 14,000 Trezor customers, though Trezor says its…
Beacon CRM Breach Traces Back to Leaked AWS Key, Over 1,000 Charities Affected
UK nonprofit CRM provider Beacon says attackers used a compromised AWS access key found in public JavaScript build files to exfiltrate its…
Attackers Exploit Critical VMware vCenter Flaw CVE-2026-59310 Within Days of Patch
An APT actor is exploiting a critical directory traversal and RCE bug in VMware vCenter's Syslog server, hitting over 360 IP addresses…
ShieldBreak Zero-Day Bypasses Microsoft Defender Patch, Grants SYSTEM Access
A new PoC dubbed ShieldBreak sidesteps Microsoft's fix for the RoguePlanet Defender flaw, letting attackers escalate to SYSTEM on fully patched Windows…
Cisco Warns of Actively Exploited ASA/FTD VPN Flaw Causing Device Crashes
A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software is being exploited to remotely crash devices via crafted HTTP requests…
Microsoft Fixes 398 Flaws, Patches Actively Exploited Windows Kernel Driver Zero-Day
August's Patch Tuesday closes 398 vulnerabilities, including a zero-day in a core Windows networking driver that attackers are already using to gain…
Microsoft’s August Patch Tuesday Fixes Nearly 400 Flaws, One Under Active Attack
Microsoft's latest security update addresses 398 vulnerabilities, including an actively exploited Windows privilege escalation bug, as AI-assisted discovery continues to drive record…
Mozilla Rotates Firefox GPG Signing Key After Accidental GitHub Exposure
Mozilla revoked and replaced a GPG signing subkey used for Firefox and Thunderbird Linux artifacts after finding an unencrypted copy in a…
CISA Confirms Active Exploitation of Critical Kemp LoadMaster RCE Flaw
A command injection bug in Progress Kemp LoadMaster, tracked as CVE-2026-8037, is being actively exploited in the wild, prompting CISA to add…
Former Medusa Affiliate Deploys New StormEncryptor Ransomware
Microsoft says China-linked threat actor Storm-1175 has pivoted from Medusa to a new C++ ransomware strain, likely exploiting an authentication-bypass flaw in…
Critical Flaws in Belgian eID Software Exposed 2 Million Users to Identity Theft
A researcher at DEF CON detailed now-patched vulnerabilities in Connective's digital identity browser extension that let malicious websites steal eID PINs, forge…
CISA Orders Federal Patch on Actively Exploited LoadMaster Flaw
A critical unauthenticated command injection bug in Progress Kemp LoadMaster is being exploited in the wild after researchers published proof-of-concept code, prompting…