A new CVSS 10.0 vulnerability, CVE-2026-29000, was published on March 4, 2026, allowing attackers to bypass authentication in the pac4j-jwt library, enabling impersonation of any user, including administrators. This…
The University of Phoenix experienced a data breach affecting 3.5 million individuals, attributed to the Clop ransomware group exploiting a zero-day vulnerability in Oracle's enterprise software. The attackers accessed…
Neurotechnology is expanding beyond clinical applications, increasing the risk of data theft and exploitation of sensitive neurological and biometric data. The U.S. and China are competing in neurotechnology…
Security debt is accumulating as organizations delay necessary security fixes, leading to increased cyber risks. This phenomenon, highlighted in ISACA's research, includes unresolved vulnerabilities, unsupported…
Since April 2026, over 1 million phishing emails have been detected using a technique called text salting to evade AI-powered email security filters. This method involves embedding benign text within malicious emails to…
Springfield Hospital in Vermont reported a data breach involving unauthorized access to an employee email account. The breach was discovered on December 17, 2025, and affected 41 Massachusetts residents. Personal…
Security Operations Centers (SOCs) are facing significant alert fatigue, with an average of 2,992 security alerts generated daily, leading to 63% going unaddressed. This phenomenon, akin to alarm fatigue in healthcare,…
Infostealer malware is increasingly exposing enterprise identity credentials, with 16% of infections involving Single Sign-On or identity provider details, according to Flare's analysis of 18.7 million logs from 2025. A…
Recent evaluations show that Claude AI models can successfully execute multistage attacks on networks with dozens of hosts using only standard, open-source tools. This development indicates a significant reduction in…