Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and…
Technology & Cybersecurity Intelligence
Curated security alerts, vulnerabilities, operating-system updates, cloud and AI news, and vendor advisories from trusted sources.
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and…
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data,…
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts…
Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business…
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's…
Oracle Linux has released kernel updates addressing several vulnerabilities, including CVEs for KVM checks and network attribute handling, available for x86_64, aarch64, and source…
Oracle Linux has released an update for version 10, addressing CVE-2026-58459, which fixes a command injection vulnerability in gpsprof and includes updated RPMs for…
Oracle Linux 9 has received updated RPM packages addressing security vulnerabilities related to KVM and network functionalities, including specific CVEs for improved stability and…
Oracle has released updated RPMs for Oracle Linux 9 addressing several vulnerabilities, including CVEs related to KVM and x86 architecture improvements and robustness against…
Oracle Linux has released an update for version 8 that includes new rpms addressing security vulnerabilities CVE-2026-64531, CVE-2026-64561, and CVE-2026-68480.
Oracle Linux 8 has released updated RPMs addressing various vulnerabilities, including CVE-2026-68480, alongside multiple patches improving security and functionality across system components.
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]
Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal…
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents…
Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS…
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing…
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no…