Trump Mobile Website API Flaw Exposed Data of Over 27,000 Customers
A security researcher discovered an API vulnerability in the Trump Mobile website that leaked names, addresses, and order details of over 27,000 customers via simple POST requests.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,764 stories synthesized.
A security researcher discovered an API vulnerability in the Trump Mobile website that leaked names, addresses, and order details of over 27,000 customers via simple POST requests.
Proton Pass now lets users grant AI agents limited, auditable access to stored credentials through AI access tokens, with full activity logging and end-to-end encryption.
Keepnet's voice and SMS phishing simulation data is included in the 2026 Verizon DBIR for the first time, revealing a 40% higher click rate for phone-based phishing.
Unit 42 warns that nation-state threat actors are actively weaponizing the open-source ROADtools framework for Azure AD reconnaissance, token theft, and persistent cloud access.
CISA has launched a new nomination form enabling researchers, vendors, and industry partners to directly submit vulnerabilities for inclusion in the Known Exploited Vulnerabilities (KEV) catalog, aiming to speed up defensive action.
The Cloud Atlas advanced persistent threat group remains active into 2026, targeting government and commercial organizations in Russia and Belarus with new VBCloud and PowerShower backdoors delivered via phishing emails.
The FBI warns of Kali365, a PhaaS platform that steals Microsoft 365 access tokens via device code phishing, bypassing MFA without requiring credentials.
MIT CSAIL researchers have released Fractal, a custom operating system designed to eliminate measurement noise in microarchitecture reverse engineering, and used it to discover undocumented behavior in the Apple M1 branch predictor.
ESET researchers uncovered a network of fraudulent FIFA World Cup websites using typosquatting and phishing kits to steal money and personal data from fans seeking tickets and merchandise ahead of the 2026 tournament.
SANS ISC analysts have dissected a cross-platform Node.js stealer that targets browser credentials and cryptocurrency wallet extensions across Windows (WSL), macOS, and Linux systems.
Visa's Spring 2026 Biannual Threats Report warns that AI-enabled impersonation and social engineering are fueling a surge in consumer scams, even as token fraud and enumeration losses decline.
North Korea-aligned threat actor Void Dokkaebi has updated its InvisibleFerret information stealer, compiling Python malware into Cython binaries to bypass script-based security tools.
A data breach at German billing service Unimed exposed sensitive patient and billing data from multiple university hospitals, affecting tens of thousands.
Canadian authorities arrested 23-year-old Jacob Butler, alias 'Dort,' for operating the Kimwolf IoT botnet that launched record-breaking DDoS attacks of nearly 30 Tbps.
Aikido researchers found that Google API keys stay valid for up to 23 minutes after deletion due to slow propagation, allowing attackers to run up charges, exfiltrate Gemini data, and exploit auto-billing tier upgrades.
CISA has added CVE-2025-34291 (Langflow) and CVE-2026-34926 (Trend Micro Apex One) to its Known Exploited Vulnerabilities catalog due to active exploitation.
A batch of 25 vulnerabilities was disclosed in Open ISES Tickets, spanning SQL injection, hardcoded secrets, TLS bypass, and XSS, all fixed in version 3.44.2.
Google inadvertently published technical details of an unpatched Chromium vulnerability that lets JavaScript run in the background after the browser is closed, enabling remote code execution and potential botnet creation.
A Ukrainian co-founder of the Forsage crypto Ponzi scheme has been extradited to the U.S., while separate exploits drained over $11M from Verus Bridge and $10.7M from ThorChain.
Wordfence reported 78 vulnerabilities in 62 WordPress plugins and 2 themes during the week of May 11–17, 2026, with 66 patched and 12 still unpatched, including 3 critical-severity flaws.
CISA published an advisory for nine UEFI firmware vulnerabilities in ABB B&R industrial PCs that could let network attackers execute remote code, cause denial of service, or poison DNS caches.
CISA has issued an advisory for three vulnerabilities in ABB B&R Automation Runtime, including a session hijack flaw (CVE-2025-3449) that could allow unauthenticated attackers to take over remote sessions.
CISA has issued an advisory for over 20 vulnerabilities in ABB B&R Automation Studio, including critical SQLite flaws with CVSS scores up to 9.8 that could allow remote code execution.
CISA has issued an advisory for CVE-2022-4304, a timing-based side-channel vulnerability in OpenSSL affecting Hitachi Energy GMS600 versions 1.3.0 and 1.3.1, which could allow attackers to decrypt TLS traffic.