en
CVE-2026-20230: Cisco Unified CM SSRF → Root — Tor-Routed Webshell Drops Confirmed, Patch Now
Technical root cause of the Cisco Unified CM SSRF vulnerability exploited in the wild to drop Tor-routed root webshells.
en
Technical root cause of the Cisco Unified CM SSRF vulnerability exploited in the wild to drop Tor-routed root webshells.
en
How threat group Icarus weaponized Klue OAuth app tokens to silently extract Salesforce data across hundreds of security vendors.
en
How extortion group World Leaks breached Tata Electronics and leaked 630 GB of proprietary Apple and Tesla engineering assets.
en
A week defined by a novel ransomware C2 technique abusing Microsoft's own relay infrastructure, the sixth Cisco SD-WAN zero-day of the year, a coordinated campaign stealing AI API keys from 70,000 developer IDE installs, a supply chain attack backdooring 144 npm packages via a stale contributor account,
en
How typosquatted npm packages targeting the Mastra AI agent framework infected 144 downstream enterprise packages with a cross-platform RAT.
en
Global telemetry analysis of FortiBleed: mass unauthenticated credential extraction targeting 73,932 Fortinet appliances.
en
Security breakdown of 15 malicious JetBrains IDE plugins stealing OpenAI, Anthropic, and AWS API keys from 70,000 developers.
en
How DragonForce ransomware operators abused Microsoft Teams TURN server relays to bypass firewall egress filtering for C2 traffic.
en
Technical root cause and remediation for the actively exploited Cisco SD-WAN Manager path traversal flaw.
en
Weekly briefing: Oracle PeopleSoft zero-day exploited by ShinyHunters, Chrome V8 in-browser RCE, and TanStack Mini Shai-Hulud worm.
en
Technical root cause for the unauthenticated OS command injection vulnerability in Fortinet FortiSandbox appliances.
en
How threat actor TeamPCP deployed the Mini Shai-Hulud worm to poison TanStack packages and compromise developer build environments.