SolarWinds Serv-U Flaw Lets Attackers Crash Servers Without Logging In
CISA confirms active exploitation of CVE-2026-28318, a Serv-U denial-of-service flaw requiring no credentials. Federal agencies must patch by June 19.
CISA confirms active exploitation of CVE-2026-28318, a Serv-U denial-of-service flaw requiring no credentials. Federal agencies must patch by June 19.
Attackers breached the WFP's Gaza self-registration platform on May 14, stealing names, ID numbers, phone numbers, and location data from roughly 600,000 househ
Agentic AI is moving into defense networks fast. The security infrastructure underneath it isn't keeping pace.
IronWorm and a new Miasma variant have compromised over 50 npm packages, stealing credentials and self-propagating through GitHub repositories.
A cryptominer was found inside the Windows version of Hola Browser after a supply chain compromise went undetected until routine certification checks flagged it
ESET has identified Android spyware called Asin spreading through fake news, PDF, and war map apps targeting Arabic-speaking users since early 2025.
CVE-2026-20230 lets unauthenticated attackers write files and escalate to root. A public PoC exists and the version 15 patch isn't due until September.