IncidentVPN Breach Hits 70+ Banks in 14 Days
Summary of the Incident A single unpatched VPN vulnerability in Marquis Software s platform compromised over seventy financial institutions. This vulnerability was present in the production infrastruc
Expert perspectives on application security, compliance, and emerging threats
IncidentSummary of the Incident A single unpatched VPN vulnerability in Marquis Software s platform compromised over seventy financial institutions. This vulnerability was present in the production infrastruc
IncidentWhat Happened Hola Browser s Windows distribution was compromised through its software supply chain, resulting in a cryptocurrency miner being bundled with legitimate installations. The malicious exec
IncidentWhat Happened On January 8, 2025, CISA added CVE-2024-21182 to its Known Exploited Vulnerabilities catalog. This vulnerability affects Oracle WebLogic Server and allows remote code execution. Oracle r
IncidentIncident Overview The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-21182 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch Oracle WebLogic S
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-9082, a critical SQL injection vulnerability in Drupal, to its Known Exploited Vulnerabilities (KEV) catalo
IncidentOn February 19, 2025, Ghost CMS released version 6.19.1, addressing CVE-2026-26980, a critical SQL injection vulnerability affecting versions 3.24.0 through 6.19.0. This flaw allowed attackers to read
IncidentOn a quiet Tuesday, the Laravel-Lang organization s PHP localization packages became a delivery mechanism for credential theft across Windows, Linux, and macOS systems. More than 700 compromised packa
IncidentWhat Happened Drupal disclosed CVE-2026-9082 , a SQL injection vulnerability in its database abstraction API that allows unauthorized database access and potential remote code execution. The flaw affe
IncidentIncident Overview On April 22, attackers published a malicious version of the Bitwarden CLI package to npm. This compromised package was available for about 90 minutes before it was detected and remov
IncidentWhat Happened Between late March and early April 2025, attackers began exploiting CVE-2026-42945 , a critical vulnerability in NGINX that allows denial-of-service attacks and potential remote code exe
IncidentIncident Overview Attackers compromised the node-ipc npm package by exploiting an expired domain linked to a maintainer s account. They published malicious versions (11.0.0, 11.1.0, and 12.0.0) contai
IncidentWhat Happened On April 13, Microsoft rejected a security researcher s vulnerability report for Azure Backup for AKS (Azure Kubernetes Service). The researcher, Justin O Leary, identified a privilege e
IncidentOn May 14, 2026, three malicious versions of node-ipc—a package with millions of weekly downloads—were published to npm. These versions (9.1.6, 9.2.3, and 12.0.1) contained a credential-stealing paylo
IncidentWhat Happened TeamPCP compromised the Checkmarx Jenkins AST plugin in a second supply chain attack, using credentials obtained from an earlier breach. The attackers gained write access to the plugin s
IncidentWhat Happened SAP s May 2026 security updates addressed 15 vulnerabilities across its enterprise software portfolio. Two critical flaws stand out for their exploitability and potential impact: CVE-202
IncidentWhat Happened In early 2025, HackerOne paused its bug bounty program due to an overwhelming increase in vulnerability discoveries, driven by AI-assisted research. This wasn t a breach or technical fai