Ex-IBM Exec Sues IBM and AT&T, Alleging Cover-Up of Major Government Hacks
A former IBM threat intelligence executive has filed a lawsuit accusing IBM and AT&T of hiding significant cybersecurity failures and breaches from government clients.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,785 stories synthesized.
A former IBM threat intelligence executive has filed a lawsuit accusing IBM and AT&T of hiding significant cybersecurity failures and breaches from government clients.
Key findings • Seven vulnerabilities disclosed together for Altium Enterprise Server and Altium 365 on June 5, 2026. • Critical path traversal flaws allow arbitrary file read/write for authen…
Toshiba and Muji websites displayed deceptive login prompts, a consequence of a compromised third-party JavaScript service, polyfill[.]io, potentially designed to steal user credentials.
A sophisticated extortion group, known as UNC3753 or Luna Moth, is employing a dual-pronged attack strategy, combining social engineering via fake help desk calls with physical office visits to steal data using USB drives.
A malicious Python package named 'parsimonius' was discovered on PyPI, impersonating the legitimate 'parsimonious' library and deploying a Telegram-based backdoor to harvest sensitive data.
Cybercriminals are leveraging legitimate system utilities, known as Living-off-the-Land Binaries and Scripts (LOLBAS), to execute attacks with unprecedented speed and stealth, making traditional detection methods insufficient.
Back-office services provider Conduent Business Services has disclosed that its 2024 data breach now impacts over 62.2 million individuals, more than doubling the initial estimate and positioning it as one of the largest health data breaches on record.
Key findings • Fifteen HAX CMS vulnerabilities disclosed together on June 5, 2026. • Critical flaws include RCE via file overwrite and private key extraction. • Stored XSS vulnerabilities…
A new Gafgyt botnet variant, C0XMO, is spreading rapidly by exploiting a critical vulnerability in DD-WRT firmware, targeting multiple Linux architectures with a modular design.
Multiple US federal agencies have issued a joint warning about cyberattacks targeting Internet-exposed automatic tank gauge (ATG) systems, urging immediate action to secure these critical infrastructure components.
CISA has added CVE-2026-28318, a SolarWinds Serv-U vulnerability, to its Known Exploited Vulnerabilities catalog due to active exploitation.
Key findings • Seven critical and high severity vulnerabilities disclosed in Termix SSH platform. • Critical OS command injection flaws in file manager and SSH tunnel endpoints. • Broken …
Key findings • Eleven vulnerabilities in Arista EOS disclosed in a single batch on June 4-5, 2026. • Critical flaws (CVE-2024-27892, CVE-2024-27890) affect OpenConfig, allowing unauthorized c…
Key findings • Three command injection vulnerabilities disclosed for D-Link DWR-M920 routers. • All vulnerabilities are rated medium severity with a CVSSv3 score of 6.3. • Exploits for al…
Chinese espionage group UNC5221, also known as VerdantBamboo, is leveraging the Brickstorm backdoor alongside new malware like Plenet and AgentPSD to achieve long-term access to compromised Microsoft 365 environments.
Rapid7's Metasploit Framework has been updated with new modules targeting critical vulnerabilities in Apache ActiveMQ and Gogs, alongside a tool for enumerating Windows kernel pointers.
The OWASP Incubator Project has released CVE Lite CLI, a free, open-source command-line tool designed to help developers quickly identify and address vulnerable software dependencies.
Key findings • 14 vulnerabilities in Nocodb disclosed simultaneously on June 5, 2026. • Issues include stored XSS, SQL injection, path traversal, and SSRF. • XSS vulnerabilities found in …
A new Android spyware, Asin, is targeting Arabic-speaking users by distributing malware through fake websites mimicking news, utility, and war map applications.
Researchers are developing proof-of-concept AI worms that can autonomously seek, adapt to, and exploit vulnerabilities across diverse environments, signaling a new era of sophisticated cyberattacks.
The 2026 Verizon Data Breach Investigations Report (DBIR) identifies the web browser as a critical attack surface, with rising threats including Shadow AI, credential abuse, and malicious extensions.
A sophisticated new variant of the SHub Stealer malware, dubbed 'Reaper,' is targeting macOS users by automating infection through fake software websites and script editors, aiming to steal browser credentials and cryptocurrency.
Millions of users are at risk as malicious Google Chrome extensions secretly harvest conversations from popular AI platforms like ChatGPT, Claude, Copilot, Gemini, and DeepSeek.
A groundbreaking prototype of an AI-powered internet worm has been developed, capable of running its own large language model on compromised systems.