SQL Server is a technology platform tracked across 27 threat clusters and 42 intelligence report mentions on ThreatCluster. First observed October 29, 2025; most recent activity July 18, 2026.
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
On March 10, 2026, Microsoft released its Patch Tuesday updates, fixing 79 vulnerabilities, including two zero-day flaws. The updates address critical vulnerabilities across various products, with one zero-day actively…
Microsoft Office Excel has multiple vulnerabilities that allow unauthorized attackers to execute code locally. These include an out-of-bounds read, use after free, untrusted pointer dereference, heap-based buffer…
In June 2026, a new ransomware family named Spirals executed a double extortion attack against an IT services company in South Asia, completing the operation in under 24 hours. The attackers gained initial access by…
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
Microsoft has disclosed a critical zero-day vulnerability in SQL Server, tracked as CVE-2026-21262, which allows authenticated attackers to escalate their privileges to the highest administrative level on affected…
Ernst & Young LLP (EY) has confirmed a data breach involving unauthorized access to a third-party IT service management platform used for tax-related work. The breach, which occurred between March 28 and April 12, 2026,…
A security researcher, known as Chaotic Eclipse, has publicly released exploit code for a zero-day vulnerability in Windows, dubbed BlueHammer, allowing local privilege escalation to SYSTEM or elevated administrator…
A vulnerability in Microsoft Authenticator for Android and iOS could enable malicious apps on the same device to intercept authentication codes or sign-in links. This issue affects users of both platforms who utilize…
A vulnerability in SQL Server, identified as CVE-2026, enables authorized attackers to elevate privileges over a network due to improper validation of input and SQL injection flaws. This issue affects users of SQL…