100Articles
9Categories
2026-04-16Date
🐛
Nginx-UI Flaw Actively Exploited to Enable Full Server Takeover
KEV
🐛
Splunk Enterprise and Cloud Platform Exposed to Dangerous RCE Vulnerability
🐛
Cisco Webex Vulnerability Allows User Impersonation Attacks
🐛
New PoC Exploit Published for Microsoft Defender 0-Day Flaw
🐛
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
🐛
Behind the Mythos hype, Glasswing has just one confirmed CVE
🐛
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
KEV
🐛
NVD shifts strategy to deal with a CVE backlog.
🐛
Too many flaws, not enough time.
🐛
NIST cuts down CVE analysis amid vulnerability overload
KEV
🐛
Cisco Systems issues three advisories for critical vulnerabilities in Webex, ISE
⚠️
McGraw Hill - 13,500,136 breached accounts
⚠️
Konform Browser - Open source web browser taking privacy, security and freedom to the next level
⚠️
Who is winning the scam game?
⚠️
AI Content Hijacks Google Discover to Deliver Malicious Alerts
⚠️
UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign
⚠️
Cisco FMC Zero-Day Among 31 High-Impact Vulnerabilities Exploited in March
KEV
⚠️
Chrome Privacy Vulnerability Exposes Users via Fingerprinting and Header Leaks
⚠️
Critical Cisco ISE Flaws Let Remote Attackers Execute Malicious Code
⚠️
Sniffnet 1.5: Welches Programm funkt nach Hause?
⚠️
Human Trust of AI Agents
⚠️
Hackers Exploit n8n Webhooks to Spread Malware
⚠️
The endless CISO reporting line debate — and what it says about cybersecurity leadership
⚠️
PowMix botnet targets Czech workforce
⚠️
Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever
KEV
⚠️
Fake ProtonVPN, game mod sites spread NWHStealer in new Windows malware campaign
⚠️
Microsoft’s Windows Recall still allows silent data extraction
KEV
⚠️
Microsoft, Salesforce Patch AI Agent Data Leak Flaws
⚠️
PHP Composer flaws enable remote command execution via Perforce VCS
⚠️
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
⚠️
Vom BlueHammer-Autor: Neuer Windows-Zeroday verschafft Adminrechte
⚠️
AI platform n8n abused for stealthy phishing and malware delivery
⚠️
EU’s official age verification app found exposing sensitive user data
⚠️
Fake Proton VPN sites are pushing NWHStealer malware to Windows users
⚠️
Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic
⚠️
EU’s official age verification app found exposing sensitive user data; also EU Age Verification can be bypassed using their own infrastructure
⚠️
The Q1 vulnerability pulse
⚠️
Foxit, LibRaw vulnerabilities
⚠️
Beating the Mythos clock: Using Tenable Hexa AI custom agents for automated patching
⚠️
McGraw-Hill Confirms Data Exposure, Hackers Claim 45M Salesforce Records Leaked
⚠️
RCE by design: MCP architectural choice haunts AI agent ecosystem
⚠️
When “No Exploit” Becomes One
⚠️
The AI "Vulnpocolypse" Is Real? - PSW #922
📋
Critical Chrome Flaws Allow Arbitrary Code Execution – Patch Immediately
📢
Insurance carriers quietly back away from covering AI outputs
📢
Spionageangst im Bendlerblock: Pistorius verbannt Privat-Handys aus Sitzungen
📢
Early Results From KnowBe4’s AI Agents Show Easier Administration and Lower Cyber Risk
🔥
How Nations Hack, Spy, and Win
🔥
Sweden reports cyberattack attempt on heating plant amid rising energy threats
🔥
Booking.com breach gives scammers what they need to target guests
🔥
McGraw Hill data breach incident exposed 13.5 million accounts
🔥
[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment
🔥
UAC-0247 Hits Hospitals, Governments With Browser and WhatsApp Data Theft
🔥
Autovista blames ransomware for service disruption • The Register
🔥
Cookeville hospital notifies 337K after hack​ | Cybernews
KEV
🔥
Malicious WordPress Plugins with Backdoors Compromise Thousands of Websites
🔥
Cookeville Regional Medical Center hospital data breach impacts 337,917 people
KEV
🔥
Here's What Agentic AI Can Do With Have I Been Pwned's APIs
🕵️
ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894, (Thu, Apr 16th)
🕵️
Fake Adobe Reader Download Drops ScreenConnect via Fileless Loader
🕵️
Russian Hosting Tied to 1,250+ C2 Servers Across 165 Providers
🕵️
Two U.S. Nationals Sentenced in $5 Million DPRK Remote Worker Laptop Farm Scheme
🕵️
From clinics to government: UAC-0247 expands cyber campaign across Ukraine
🕵️
BlobPhish: The Phantom Phishing Campaign Hiding in Browser Memory
🕵️
US Moves Toward Mandatory Data Center Energy Reporting as EIA Pilot Expands
🕵️
Google, Microsoft, Meta Tracking You Even if You Opt Out - New Research
🕵️
French cops free mother and son after crypto kidnapping • The Register
🕵️
AI adoption is outpacing the safeguards around it - Help Net Security
🕵️
WordPress plugins injected with malicious code​ | Cybernews
🕵️
Fortinet Patches Critical FortiSandbox Vulnerabilities - SecurityWeek
🕵️
Quantum-safe encrypted cloud storage Tuta Drive debuts in closed beta
🕵️
AI Security Arms Race Begins
🕵️
Adobe Expands Firefly Into AI-Powered Editing Assistant Across Creative Apps
🕵️
Two Americans sentenced for helping North Korea steal $5 million in fake IT worker scheme
🕵️
Major Disney Layoffs: 1,000 Jobs Cut in Tech-Driven Shakeup
🕵️
EU Declares New Digital Age Verification App Ready for Deployment
🕵️
New MacBook Pro Overhaul Expected with OLED, Touchscreen, and M6 Chips
🕵️
NTT Research Launches Scale Academy to Bring Lab Technology to Market
🕵️
The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic
🌐
Anthropic vs Washington.
🌐
A fake Slack download is giving attackers a hidden desktop on your machine
🌐
Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks
🎙️
Extending zero trust beyond the endpoint with Rob Allen from ThreatLocker
📡
Chrome-Update stopft 31 Sicherheitslücken, davon fünf kritische
📡
Cisco: Kritische Codeschmuggel-Lücken in ISE und mehr geschlossen
📡
Anonymisierendes Linux: Notfallupdate auf Tails 7.6.2 schließt Flatpak-Lücke
📡
More than pretty pictures: Wendy Bishop on visual storytelling in tech
📡
Hidden Passenger? How Taboola Routes Logged-In Banking Sessions to Temu
📡
Fashion retailer Express left customers’ personal data and order details exposed to the internet
📡
Browser Guard gets even better with Access Control
📡
“iCloud storage is full” scam is back, and now it wants your payment details
📡
Android Canary: Google testet überarbeitetes Kontextmenü für App-Icons
📡
Gimp: Ungepatchte Lücke erlaubt Codeschmuggel mit GIFs
📡
ÖPNV-Expressmodus-Funktion beim iPhone: YouTuber zeigen potenziellen Angriff
📡
„Power Off“: BKA geht gegen DDoS-Angebote vor
📡
It’s not just you — Bluesky is (sorta) down
📡
Die Natur ist unsere Quelle der Zufälligkeit: zum Tode von Michael O. Rabin
📡
European police email 75,000 people asking them to stop DDoS attacks
📡
Cisco fixed four critical flaws in Identity Services and Webex
📡
Treasury Secretary holds a meeting to cover risks related to Anthropic’s new model.