Wiz has disclosed a GitHub Actions workflow injection flaw in a Snowflake public repository that could allow crafted GitHub issues to trigger command execution and expose internal Jira credentials.
A critical vulnerability in the Forminator WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute remote code on vulnerable websites.
Security researchers have disclosed a two stage exploit chain affecting Unisoc chipsets that can achieve Android kernel access through VoLTE video calls with no vendor patch currently available.
Fortinet researchers have identified the Evooo1Bot Linux botnet, which exploits multiple known vulnerabilities to compromise internet facing devices and convert them into SOCKS5 proxy nodes.
Researchers have linked active exploitation of VMware vCenter vulnerability CVE 2026 59310 to a suspected China nexus threat actor deploying backdoors, reverse SSH tools and Babuk derived ransomware.
CTM360 has uncovered a large scale recruitment phishing campaign using Browser In Browser credential traps, fake interview pages and live MFA relay attacks to target enterprise accounts.
Cohesity will host a webinar on August 27 to discuss Microsoft 365 data protection, immutable backups, encryption and isolated storage for improving cyber resilience.
Security researchers have observed exploitation attempts targeting SAP Commerce Cloud vulnerability CVE 2026 58231 only days after SAP released a patch for the critical remote code execution flaw.
Kaspersky has identified a new CoolClient malware variant linked to Mustang Panda that deploys a signed Windows kernel rootkit to hide malicious activity and strengthen persistence on compromised systems.
Apple has issued new spyware threat notifications to users in 110 countries, warning that mercenary spyware attacks continue to target journalists, activists, politicians, diplomats and other high risk individuals.
Security researchers warn that a newly disclosed GeoServer zero day SQL injection vulnerability is being actively targeted and could lead to remote code execution on vulnerable systems.
Broadcom researchers reveal China linked Jewelbug using the XG Web platform to conduct cyber espionage against governments and militaries while operating cryptocurrency fraud campaigns.