A new threat actor, UAT-7290, has been identified conducting cyberattacks on telecommunications infrastructure in South Asia. This operation is linked to a China-Nexus state-sponsored advanced persistent threat (APT)…
The University of Phoenix reported a data breach on November 21, 2025, resulting from the exploitation of a zero-day vulnerability (CVE-2025-61882) in Oracle EBS. This flaw allowed threat actors to execute remote code…
APT28 has actively exploited a zero-day vulnerability in MSHTML affecting all Windows versions, which has a CVSS score of 8.8. The vulnerability allows for security bypass and poses significant risks to users. A patch…
Barts Health NHS and Dartmouth College confirmed data breaches due to exploitation of a zero-day vulnerability in Oracle E-Business Suite software by Clop hackers. The breaches resulted in the compromise of personal…
Cisco Talos reported that the Secure Email Gateway is under attack due to a zero-day vulnerability. The campaign is attributed to UAT-9686, an advanced persistent threat actor believed to have connections to China.…
Logitech International reported a data breach resulting from a zero-day vulnerability in third-party software. The breach involved unauthorized access to sensitive data, including information about employees and…
Logitech has confirmed a data breach resulting from a zero-day exploit that compromised its internal IT systems. The attack, attributed to the Clop extortion group, has likely affected customer data, raising concerns…
A critical authentication vulnerability in the Appsmith low-code platform, tracked as CVE-2026-22794, has been exploited to facilitate user account takeovers. The flaw allows attackers to manipulate password reset links…
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…