Hackers Exploiting Unpatched GeoServer Zero-Day
Threat actors started exploiting an unpatched zero-day vulnerability in GeoServer hours after it was publicly disclosed, attack surface management firm WatchTowr says. The security defect,…
Threat actors started exploiting an unpatched zero-day vulnerability in GeoServer hours after it was publicly disclosed, attack surface management firm WatchTowr says. The security defect,…
GeoServer Zero-Day Is Already Being Probed. That’s the Problem Pierluigi Paganini August 15, 2026 GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE,…
“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself,…
The vast majority of companies relying on cloud infrastructure are at least partially using environments hosted by one of the big three Cloud Service Providers.…
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.…
Multinational energy giant Shell has launched an active investigation after the notorious Cl0p ransomware syndicate claimed responsibility for exfiltrating sensitive internal data. Security researchers and…
Microsoft will make passkeys the default authentication experience in Entra ID beginning September 1, 2026, and will fully retire its native SMS and voice multifactor…
A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law…
Swati KhandelwalAug 11, 2026Insider Threat / Cyber Espionage Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North…
Hardware crypto wallet provider Trezor says the personal information of nearly 14,000 people was compromised in a data breach. The incident, it says, did not…
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners Pierluigi Paganini August 15, 2026 Hackers are exploiting a macOS Screen Sharing flaw to gain root…
The revealed attack chain combines four weaknesses, including a broken authorization in the AdminService upload functionality, a path-traversal flaw dubbed “CabSlip,” weak code-signing validation that…