4 articles and related resources
The Bitwarden CLI npm package was compromised in a supply chain attack, highlighting the critical need for enhanced security measures in software dependencies.
Gunra ransomware exploits Fortinet vulnerabilities to target critical infrastructure, emphasizing the need for timely patching and robust cybersecurity practice
The March 2026 LiteLLM supply chain attack exposed sensitive data from over 2,500 organizations, highlighting critical vulnerabilities in software dependencies.
SonicWall's SMA 1000 Series appliances are under active exploitation due to critical zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410, allowing remote
WordPress has patched critical vulnerabilities CVE-2026-63030 and CVE-2026-60137, urging immediate updates to prevent potential exploits.
Microsoft's July 2026 Patch Tuesday addresses a record 622 vulnerabilities, including three critical zero-days, underscoring the importance of prompt updates.
Ubiquiti addresses seven critical vulnerabilities in UniFi OS, urging immediate updates to prevent potential exploits.
Microsoft has disclosed two critical vulnerabilities in Defender, CVE-2026-41091 and CVE-2026-45498, which are actively exploited in the wild.
The Gentlemen ransomware has rapidly become the second most active RaaS operation in 2026, exploiting FortiGate and Cisco vulnerabilities to target critical sec
Cl0p ransomware exploits zero-day vulnerabilities in MFT software, compromising thousands of organizations and highlighting the need for enhanced cybersecurity
A 42-line npm package was exploited to infiltrate multiple production environments, highlighting critical supply chain vulnerabilities.
In April 2026, a ransomware campaign exploited Veeam Backup & Replication vulnerabilities, leading to significant data loss and operational disruptions.
Microsoft identifies Storm-1175 exploiting zero-day vulnerabilities to deploy Medusa ransomware within 24 hours, targeting multiple sectors globally.
Storm-1175 exploits web vulnerabilities to deploy Medusa ransomware rapidly, emphasizing the need for robust cybersecurity measures.
The widely-used Axios npm package was compromised in a significant supply chain attack, affecting millions of applications and exposing sensitive data.
Researchers unveil 'Java-Class-Hijack,' a novel supply chain attack exploiting Java's dependency resolution and classloading, posing significant risks to applic
Recent research reveals the risks of cascading vulnerabilities in software supply chains, emphasizing the need for comprehensive security measures.
The BacAlarm study introduces a novel approach to detecting Broken Access Control violations in APIs, enhancing security by addressing data scarcity and complex
Cl0p ransomware exploits Oracle EBS zero-day vulnerabilities, compromising sensitive data across numerous enterprises and highlighting the need for robust cyber
Explore the risks of subdomain takeovers in multi-tenant platforms and discover effective strategies to prevent unauthorized access and data breaches.