A critical zero-day vulnerability in Synology's BeeStation OS allows remote code execution (RCE) on unpatched devices. The flaw, originating from a buffer overflow, has a CVSS score of 9.8, indicating severe risk.…
Synology has released an urgent security update for its DiskStation Manager (DSM) software to address a critical vulnerability, CVE-2026-32746, which could allow unauthenticated remote attackers to execute arbitrary…
A critical security vulnerability (CVE-2025-12686, CVSS 9.8) was discovered in Synology's BeeStation during Pwn2Own 2025 in Ireland. This vulnerability allows attackers to execute arbitrary code remotely due to a buffer…
Ivanti Endpoint Manager (EPM) has multiple high-severity vulnerabilities that allow attackers to write arbitrary files to disk, potentially leading to privilege escalation and malicious code execution. A security patch…
A significant phishing campaign has targeted over 5,000 businesses using Meta's Business Suite, distributing approximately 40,000 phishing emails. Attackers exploited the facebookmail.com domain and created fake…
A study by Wiz Security revealed that 65% of the Forbes AI 50 companies have leaked sensitive information, including API keys and tokens, on GitHub. The affected companies, valued collectively at over $400 billion, are…
As the 2025 holiday season approaches, fraud activity is accelerating, driven by attackers utilizing artificial intelligence (AI), automation, and stolen data. Industries such as retail, hospitality, and quick-service…