Corporate executives’ most sensitive identity data is being sold on dark web marketplaces for as little as a quarter, according to new threat intelligence from Rapid7. Unlike stolen credit cards, …
CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Citrix NetScaler ADC and NetScaler Gateway security flaw, tracked as CVE-2026-8452, to its Known Exploited Vulnerabilities catalog after confirming …
New Twitter Launches as Startup Claims Elon Musk’s X Abandoned the Twitter Name
A startup operating as Operation Bluebird, Inc. has launched early access to a new social media service on Twitter.now, positioning itself as a revival of the Twitter brand that Elon …
GitLab Fixes Claude AI Agent Flaw That Could Execute Arbitrary Commands in CI Pipeline
GitLab has released security updates to fix a high-severity vulnerability in its Duo Claude AI agent that could allow authenticated developers to execute arbitrary commands within CI pipeline contexts. The …
TP-Link Kasa Smart Home Devices Vulnerability Allows Attackers to Disrupt Device Functionality
TP-Link has disclosed a high-severity vulnerability affecting multiple Kasa smart home devices that could allow attackers on the same local network to intercept, replay, or forge device-control commands. Tracked as …
CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft SQL Server remote code execution vulnerability, tracked as CVE-2019-1068, to its Known Exploited Vulnerabilities catalog after confirming exploitation in …
Two Australians Charged Over TeamPCP Supply-Chain Attacks That Hit 1,000+ Organizations
Two Western Australian men have been charged over alleged TeamPCP supply-chain attacks that police say planted malicious open-source code and reached more than 1,000 organizations worldwide. The Australian Federal Police …
AWS Shows How Hackers Can Turn Stolen Cloud Credentials Into Full-Scale Attacks
Stolen cloud credentials can turn an incident into a wider breach. An attacker who gets a valid AWS key or session can enter as an approved user and move toward …
Multiple TeamViewer Vulnerabilities Enable Remote Code Execution Attacks
TeamViewer patched high-severity CVE-2026-16444, allowing authenticated remote-session attackers to write files to unintended locations and potentially execute code with user privileges. The issue is detailed in TeamViewer security bulletin TV-2026-1008, …
Hackers Exploit ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data
A suspected Chinese-speaking operator exploited known ownCloud and WordPress weaknesses to collect sensitive information from a Philippine nuclear research body and a marine engineering company that serves the Philippine Navy. …
