Attackers hid malware inside Oracle Database after SQL injection breach
The attackers could have simply extracted or manipulated data through SQL injection, but instead, they expanded the exploit to include long-term persistence and remote command…
The attackers could have simply extracted or manipulated data through SQL injection, but instead, they expanded the exploit to include long-term persistence and remote command…
Organizations adopting cloud and AI at scale face a tough challenge: balancing centralized security control with speed and agility across diverse teams. Enter Wiz Lens—a…
This week’s roundup covers active exploitation of Apache Tomcat and SonicWall SMA, a nearly two-decade-old Linux kernel flaw, critical bugs in N-able N-Central, Veeam ONE,…
Brand impersonation is one of the fastest growing threats facing organizations today. Bad actors create fake websites using an organization’s name, logos, and visual identity to exploit brand trust and steal a customer, partner, or employee’s credentials, money, or sensitive data.…
Swati KhandelwalAug 07, 2026Network Security / Vulnerability Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT)…
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data Pierluigi Paganini August 09, 2026 IEH was breached by a phishing attack that…
After more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people watching the recent wave of autonomous security announcements.…
Bill Swearingen has spent the past year running largely the same test, over and over again. The goal was to produce a computer-generated pattern that…
In cloud-native environments, the security of your code repositories and development pipelines is critical. The 2025 State of Code Security Report sheds light on the…
A new class of email-based attacks that exploit ordinary CSS styling code to hijack webmail interfaces, spy on user activity, and even steal passwords in…
Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain,…
Swati KhandelwalAug 07, 2026Linux / Vulnerability A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent…