Topic
Data Breaches.
16 stories of advisories, analysis, and defensive guidance in this topic.
AI automation accelerates zero-day exploitation windows forcing a shift toward preemptive defense strategies
The window between vulnerability disclosure and active exploitation is collapsing as adversaries automate attacks with AI.
Automated AI Models Discover New Software Vulnerabilities Challenging Traditional Security Defenses
AI models are now capable of identifying new software vulnerabilities, shifting the landscape for security teams.
Unauthorized access to Estée Lauder HR systems exposes financial accounts through Oracle flaw
An unauthorized third party gained access to Estée Lauder's HR management systems via a vulnerability in Oracle E-Business Suite.
Exploitation of SharePoint vulnerabilities enables remote code execution and sensitive IIS key theft
Threat actors are actively exploiting three vulnerabilities in on-premises Microsoft SharePoint Server instances to achieve remote code execution and steal sensitive IIS machine keys.
Millions of user credentials leaked following zero-day exploit in KDDI email system
A zero-day vulnerability in KDDI's email system has exposed the credentials of millions of users across several Japanese ISPs.
Unauthenticated remote code execution flaws in Joomla and Langflow added to CISA KEV catalog
CISA has added three critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation.
Unauthenticated attackers exploit critical vulnerabilities for remote code execution in Oracle E-Business Suite
Critical vulnerabilities in Oracle E-Business Suite and PeopleSoft are being actively exploited by threat actors.
CISA Catalog Update: Four Critical Vulnerabilities Under Active Exploitation Demand Urgent Patching
CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, signaling active exploitation.
ShinyHunters Breaches Expose Shift to Identity Exploitation in Cybersecurity
The ShinyHunters cybercrime collective has shifted its focus from exploiting software vulnerabilities to targeting identities and trusted access paths.
Organizations Must Secure Systems Against Top 10 AI-Driven Vulnerabilities
AI models are increasingly used to identify software vulnerabilities. Organizations must adopt proactive measures to secure their systems against these AI-driven exposures.
High-Severity DoS Vulnerability Exposes 1769 Rockwell Automation CompactLogix Controllers to Attack
Rockwell Automation's CompactLogix 5370 controllers are vulnerable to denial-of-service (DoS) attacks due to improper validation of sequence numbers and source IP addresses in the CIP protocol.
AI Models Weaponized for Vulnerability Identification: Urgent Security Measures Needed
AI models have been weaponized to identify software vulnerabilities, posing significant risks. Organizations must adopt proactive measures to secure against these AI-driven threats.
Critical Path Traversal Flaw in Langflow Exploited, Immediate Upgrade Advised
A critical path traversal vulnerability in the AI development platform Langflow (CVE-2026-5027) is being actively exploited.
Exploited Ivanti Sentry Vulnerability Grants Root Access to Attackers
Attackers are exploiting a high-severity command injection vulnerability in Ivanti Sentry, allowing them to execute code with root privileges on exposed secure mobile gateways.
ServiceNow API Flaw Exposed Customer Data: Swift Patching Advised
ServiceNow has disclosed an incident where attackers exploited an unauthenticated access flaw in a vulnerable API endpoint. This allowed them to query sensitive data from customer instances.
AI-Driven Vulnerabilities Pose New Threats, Compromising Social Media Accounts
AI-driven vulnerabilities have surfaced as a significant threat vector in cybersecurity.