Attackers exploit SharePoint CVE-2026-55040 after a Rapid7 PoC release, forging JWTs to impersonate site users or admins.
Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
Connor Riley Moucka, 26, pleaded guilty Wednesday in U.S. District Court for the Western District of Washington to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy — ...
A critical Gremlin API vulnerability exposed a path to any Cosmos DB instance, including Microsoft’s own services, before the company redesigned the platform.
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic ...
SAP development plugins for AI coding assistants, with public-source or package-registry verification tracked where available. Live tenant and system validation is ...