Cwe-327 - Use Of A Broken Or Risky Cryptographic Algorithm is a cwe tracked across 7 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed April 30, 2026; most recent activity June 30, 2026.
A new cyber threat identified by Huntress involves a fake background removal website that tricks users into executing malicious commands. Dubbed BackgroundFix, this site masquerades as a free image-editing service,…
The Aqara IAM/SSO gateway (gw-builder.aqara.com) has a critical vulnerability (CVE-2026-50086) that allows unauthorized access to cryptographic operations involving the platform's signing key. This flaw enables…
Recent identity-based attacks have exploited vulnerabilities in authentication systems, targeting credentials and identity infrastructure. Notable incidents include the compromise of over 18,000 routers by APT28 to…
A security researcher discovered a critical vulnerability in AMD's auto-updater software that allowed remote code execution via man-in-the-middle attacks. The flaw was reported on February 6, 2026, but AMD initially…
On World Password Day, Kaspersky revealed that 60% of MD5-hashed passwords can be cracked in under an hour using a single Nvidia RTX 5090 GPU, with 48% crackable in under a minute. The study analyzed over 231 million…
Recent security updates for Fedora 44 and 43 address significant vulnerabilities in the Ongres database authentication mechanisms. The updates fix silent channel-binding authentication downgrades via unsupported…
SUSE has released updates addressing a critical buffer overflow vulnerability (CVE-2026-25506) in the munge package, affecting multiple SUSE Linux versions. The vulnerability, which was published on February 10, 2026,…