Log4j is a vulnerability tracked across 14 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity June 3, 2026.
A new CVSS 10.0 vulnerability, CVE-2026-29000, was published on March 4, 2026, allowing attackers to bypass authentication in the pac4j-jwt library, enabling impersonation of any user, including administrators. This…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…
The article discusses the fifth volume of AttackIQ’s Ransom Tales series, which simulates the tactics of ransomware families REvil, DarkSide, and BlackMatter. These emulations are designed to help organizations validate…
Burp Suite has upgraded its scanning capabilities to detect critical React2Shell vulnerabilities in JavaScript applications. Both editions of Burp Suite now include the latest detection logic, allowing users to validate…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, is being actively exploited in the wild. This flaw…
A critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, allows remote code execution (RCE) without authentication. Discovered by Searchlight Cyber researchers, the flaw has been actively…
A critical remote code execution vulnerability, tracked as CVE-2025-61757, has been identified in Oracle Identity Manager. This flaw allows unauthenticated attackers to execute code remotely and has been actively…
Software supply chain security has gained prominence, now ranking third on the OWASP Top 10 list for 2025. This shift reflects a rise in attacks targeting the foundational components of software, which exploit trust in…
Apache Logging Services has disclosed a critical vulnerability in Log4j Core that allows attackers to intercept sensitive log data. This flaw affects versions 2.0-beta9 through 2.25.2, specifically in the Socket…