Get the daily digest
A compact daily briefing of the highest-signal cybersecurity stories, in your inbox. Email digest is coming soon.
Daily cybersecurity intelligence
Raw, actionable daily security news for defenders tracking exploited vulnerabilities, ransomware, breaches, malware, cloud risk, supply-chain security, and practical detection guidance.
Hard-coded credentials and missing authentication in Furuno FA-50 AIS transponders allow attackers on the internal vessel network to alter device settings and identification numbers.
More top stories
Attackers are actively exploiting a critical directory traversal vulnerability in the VMware vCenter Syslog server to gain remote code execution.
Critical vulnerabilities in the ANDRITZ HIPASE-250 system allow unauthenticated attackers to steal passwords, view live process data, and suppress audit logs.
Critical flaws in the Siemens License Server (SLS) could allow attackers to read arbitrary files remotely or gain full root access via local privilege escalation.
A high-severity out of bounds read vulnerability in Siemens Parasolid could allow an attacker to execute arbitrary code or crash the application.
Ivanti has released critical updates to address multiple high-severity vulnerabilities in Endpoint Manager (EPM) that could lead to credential theft and unauthorized S3 bucket control.
Lazarus Group is exploiting a Windows kernel vulnerability to escalate privileges and deploy backdoors via fake job offers.
🚨 Critical flaw in Adobe ColdFusion 2025 enables full system compromise. Attackers can execute arbitrary commands without any user interaction or authentication.
Attackers are actively exploiting a critical authentication bypass in Microsoft SharePoint. This flaw allows unauthenticated remote users to impersonate site users or administrators and modify data.
🚨 High severity. A zero-click remote code execution flaw in Zoom's annotator function allows attackers to take over a participant's machine without any user interaction.
Microsoft has released a massive update addressing 398 security flaws, including one critical vulnerability currently being exploited in the wild.
Critical flaws in Mira hormone monitor firmware and cloud infrastructure expose users to sensitive reproductive health data theft and full account hijacking.
Microsoft's August 2026 Patch Tuesday addresses 400 vulnerabilities, including one actively exploited zero-day used by the Lazarus group to deploy kernel-mode rootkits.