115Articles
8Categories
2026-03-23Date
πŸ›
AL26-005 – Critical vulnerability impacting Microsoft SharePoint Server – CVE-2026-20963
πŸ›
Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability
KEV
πŸ›
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
πŸ›
Chromium: CVE-2026-4464 Integer overflow in ANGLE
πŸ›
Chromium: CVE-2026-4463 Heap buffer overflow in WebRTC
πŸ›
Chromium: CVE-2026-4462 Out of bounds read in Blink
πŸ›
Chromium: CVE-2026-4461 Inappropriate implementation in V8
πŸ›
Chromium: CVE-2026-4456 Use after free in Digital Credentials API
πŸ›
Chromium: CVE-2026-4460 Out of bounds read in Skia
πŸ›
Chromium: CVE-2026-4457 Type Confusion in V8
πŸ›
Chromium: CVE-2026-4446 Use after free in WebRTC
πŸ›
Chromium: CVE-2026-4449 Use after free in Blink
πŸ›
Chromium: CVE-2026-4445 Use after free in WebRTC
πŸ›
Chromium: CVE-2026-4451 Insufficient validation of untrusted input in Navigation
πŸ›
Chromium: CVE-2026-4447 Inappropriate implementation in V8
πŸ›
Chromium: CVE-2026-4444 Stack buffer overflow in WebRTC
πŸ›
Chromium: CVE-2026-4455 Heap buffer overflow in PDFium
πŸ›
Chromium: CVE-2026-4452 Integer overflow in ANGLE
πŸ›
Chromium: CVE-2026-4443 Heap buffer overflow in WebAudio
πŸ›
Chromium: CVE-2026-4448 Heap buffer overflow in ANGLE
πŸ›
Chromium: CVE-2026-4441 Use after free in Base
πŸ›
CVE-2026-4438 gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
πŸ›
Chromium: CVE-2026-4454 Use after free in Network
πŸ›
Chromium: CVE-2026-4450 Out of bounds write in V8
πŸ›
CVE-2026-4437 gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response
πŸ›
Chromium: CVE-2026-4458 Use after free in Extensions
πŸ›
Chromium: CVE-2026-4440 Out of bounds read and write in WebGL
πŸ›
Hackers Exploit Quest KACE SMA Flaw to Harvest Credentials
πŸ›
CISA Warns of Craft CMS Code Injection Flaw Exploited in Active Attacks
KEV
πŸ›
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
πŸ›
ZDI-26-225: (Pwn2Own) Samsung Galaxy S25 Samsung Account Open Redirect Security Bypass Vulnerability
πŸ›
ZDI-26-224: (Pwn2Own) Samsung Galaxy S25 Samsung Account Cross-Site Scripting Remote Code Execution Vulnerability
πŸ›
ZDI-26-223: (Pwn2Own) Samsung Galaxy S25 Smart Touch Call Application Protection Mechanism Failure Information Disclosure Vulnerability
πŸ›
ZDI-26-222: (Pwn2Own) Canon imageCLASS MF654Cdw BJNP Memory Corruption Remote Code Execution Vulnerability
⚠️
Microsoft Xbox One Hacked
⚠️
Startup Accused Of Helping Fake Privacy and Security Audits
⚠️
CISA orders feds to patch DarkSword iOS flaws exploited attacks
⚠️
Aqua’s Trivy Vulnerability Scanner Hit by Supply Chain Attack
⚠️
QNAP Patches Four Vulnerabilities Exploited at Pwn2Own
⚠️
Tycoon 2FA Fully Operational Despite Law Enforcement Takedown
⚠️
⚑ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
⚠️
We Found Eight Attack Vectors Inside AWS Bedrock. Here's What Attackers Can Do with Them
⚠️
The β€˜Urgency Trap’: Why Time Pressure is Your Biggest Email Red Flag
⚠️
Critical QNAP QVR Pro Flaw Could Let Remote Attackers Access Systems
⚠️
Faster attacks and β€˜recovery denial’ ransomware reshape threat landscape
⚠️
Chrome ABE bypass discovered: New VoidStealer malware steals passwords and cookies
⚠️
Behavioral XDR and threat intel nab North Korean fake IT worker within 10 days of hire
⚠️
Why US companies must be ready for quantum by 2030: A practical roadmap
⚠️
The insider threat rises again
⚠️
cpe-guesser 2.0 released
⚠️
Patch Now: Oracle's Fusion Middleware Has Critical RCE Flaw
⚠️
Trivy vulnerability scanner backdoored with credential stealer in supply chain attack | CSO Online
⚠️
Why One-Time Pen Testing Isn’t Enough
⚠️
Someone has publicly leaked an exploit kit that can hack millions of iPhones
⚠️
A Vulnerability in Oracle Products Could Allow for Remote Code Execution
⚠️
I Built 7 MCP Servers for Security Tools. The Protocol Was the Easy Part.
⚠️
Someone has publicly leaked an exploit kit that can hack millions of iPhones
⚠️
Securing the AI Enterprise β€” Introducing Prisma AIRS 3.0
⚠️
The Cryptographic Reset Has Begun
⚠️
M-Trends 2026: Data, Insights, and Strategies From the Frontlines
⚠️
IAM policy types: How and when to use them
πŸ“‹
511,000+ End-of-Life IIS Instances Found Online, Raising Security Risks
πŸ“’
VMware security advisory (AV26-269)
πŸ“’
Microsoft Edge security advisory (AV26-268)
πŸ“’
Citrix security advisory (AV26-267)
πŸ“’
Red Hat security advisory (AV26-266)
πŸ“’
[Control systems] CISA ICS security advisories (AV26–265)
πŸ“’
Ubuntu security advisory (AV26-264)
πŸ“’
Dell security advisory (AV26-263)
πŸ“’
IBM security advisory (AV26-262)
πŸ“’
Oracle security advisory (AV26-261)
πŸ“’
Kubernetes security advisory (AV26-260)
πŸ“’
FBI warns of Handala hackers using Telegram in malware attacks
πŸ“’
β€˜CanisterWorm’ Springs Wiper Attack Targeting Iran
πŸ“’
Reflections from the Second NIST Cyber AI Profile Workshop
πŸ“’
Federal immigration agents filmed making airport arrests as Trump calls in ICE to ease security line delays
πŸ“’
CISA orders feds to patch max-severity Cisco flaw by Sunday
πŸ”₯
M-Trends 2026: Initial Access Handoff Shrinks From Hours to 22 Seconds
πŸ”₯
Chip Services Firm Trio-Tech Says Subsidiary Hit by Ransomware
πŸ”₯
Case study: How predictive shielding in Defender stopped GPO-based ransomware before it started
πŸ”₯
Libyan Refinery Targeted in Prolonged Spy Campaign With AsyncRAT
πŸ”₯
Can AI help critical infrastructure, the state of the cyber market, and weekly news - ESW #451
πŸ”₯
Trivy Compromised by "TeamPCP" | Wiz Blog
πŸ”₯
Navia Data Breach Impacts 2.7 Million - SecurityWeek
πŸ”₯
Crunchyroll probes breach after hacker claims to steal 6.8M users' data
πŸ”₯
Mazda discloses security breach exposing employee and partner data
πŸ”₯
RuneScape Boards - 222,762 breached accounts
πŸ•΅οΈ
RSAC 2026 Conference Announcements Summary (Pre-Event)
πŸ•΅οΈ
ISC Stormcast For Monday, March 23rd, 2026 https://isc.sans.edu/podcastdetail/9860, (Mon, Mar 23rd)
πŸ•΅οΈ
Tax Scam Google Ads Push BYOVD EDR Killer, Huntress Finds
πŸ•΅οΈ
SEO Poisoning Campaign Uses Fake Popular Apps to Deliver AsyncRAT
πŸ•΅οΈ
MioLab MacOS Stealer Expands With ClickFix, Wallet Theft, Team APIs
πŸ•΅οΈ
Oblivion RAT Masquerades as Play Store Update to Spy on Android Users
πŸ•΅οΈ
$30 IP-KVM Flaws Could Enable BIOS-Level Enterprise Network Attacks
πŸ•΅οΈ
FBI says Iranian hackers are using Telegram to steal data in malware attacks
πŸ•΅οΈ
AI-First Security Is Mostly Hype
πŸ•΅οΈ
Burp Anonymizer
πŸ•΅οΈ
Thousands of Magento Sites Hit in Ongoing Defacement Campaign - SecurityWeek
πŸ•΅οΈ
BurpAnonymizer
πŸ•΅οΈ
North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware
πŸ•΅οΈ
Securing the Era of Agentic AI with Prisma SASE
πŸ•΅οΈ
Prisma Browser for Business β€” A Secure Workspace for Small Business
πŸ•΅οΈ
GitHub expands application security coverage with AI‑powered detections
🌐
Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware
🌐
Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper
πŸ“‘
Trivy supply-chain attack spreads to Docker, GitHub repos
πŸ“‘
Varonis Atlas: Securing AI and the Data That Powers It
πŸ“‘
Microsoft Exchange Online service change causes email access issues
πŸ“‘
New KB5085516 emergency update fixes Microsoft account sign-in
πŸ“‘
Russian authorities block paywall removal site Archive.today
πŸ“‘
TeamPCP deploys Iran-targeted wiper in Kubernetes attacks
πŸ“‘
Tool updates: lots of security and logic fixes, (Mon, Mar 23rd)
πŸ“‘
Tycoon2FA phishing platform returns after recent police disruption
πŸ“‘
OpenAI rolls out ChatGPT Library to store your personal files
πŸ“‘
Proofpoint Redefines Email and Data Security for the Agentic Workspace