A cybersecurity firm UpGuard has found that thousands of databases hosted on Supabase can expose private information to the public internet. According to…
Category: CySecurity News – Latest Information Security and Hacking Incidents
Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks
Secure file-sharing provider Kiteworks issued an urgent advisory urging customers to power down their servers for a six-hour window following credible…
x47.c Windows Botnet Uses xAI Grok for Persistence and AI Credit Draining
A new Windows botnet called x47.c is being sold with a range of capabilities, including credential theft, distributed denial-of-service (DDoS) attacks,…
Bitget Hack Climbs to $387.5 Million as Exchange Launches Recovery Bounty and Points to North Korea
Crypto exchange Bitget confirmed on September 25 that hackers stole approximately $387.5 million from its hot and warm wallets a day earlier, revising an…
Hacking and Extortion Operation Targeting U.S. Official Ends in Conviction
A former U.S. Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for participating in a hacking and extortion campaign which…
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted
SolarWinds has issued security updates for two critical vulnerabilities in its Observability Self-Hosted product that could enable remote code execution…
Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other’s Leftover Disk Data
Cloudflare has patched a vulnerability in its Containers product that could have allowed a paying customer to pull residual data out of disk storage…
Astrana Health Data Breach Exposes Private and Confidential Information
In a cybersecurity incident, Astrana Health disclosed, attackers gained access to company servers and obtained confidential and private information. A…
CISA Adds Actively Exploited WSO2 and Adobe Commerce Flaws to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting WSO2 and Adobe Commerce to its Known…
Check Point Warns of Active Exploitation of Two Critical Pre-Authentication Vulnerabilities
Check Point has issued urgent warnings to customers following the discovery of active attacks targeting two zero-day flaws in its products. The two…
Critical Roundcube Flaw Under Active Exploitation in Code Injection Attacks
A high-severity vulnerability in Roundcube Webmail, patched in May 2026, is now being actively exploited in code injection attacks, according to the…
How an OpenAI ‘agent’ hacked Australia’s Medicare and What that Means for Governments Worldwide
In June, OpenAI gave one of its AI agents a task so unremarkable it barely warranted attention: look up public data on Australian medicine spending. What…
OnePlus Android Devices Face Root Access Risk From Unpatched Flaws
Unpatched vulnerabilities in OnePlus software can allow a malicious Android application to gain root-level control of affected devices without requesting…
F5 Fixes BIG-IP APM Zero-Day Enabling Unauthenticated RCE
BIG-IP Access Policy Manager (APM) vulnerabilities have been patched by F5 as a result of zero-day attacks utilizing this vulnerability, which allows…
OAuth Phishing Attacks Bypass Passwords by Turning User Consent Into a Security Threat
Cybercriminals are targeting something more difficult to protect with traditional password advice: the user consent. New phishing techniques called OAuth…
GitLab Email Feature Exposes Critical Security Risk
GitLab’s “Email work item to this project” feature, intended to simplify issue creation, has been found to expose a serious security vulnerability that…
A Go Worm Stole MemTensor’s CI Tokens and Shipped Backdoored Packages to npm and PyPI
On September 23, 2026, an attacker spent roughly five hours poisoning two packages belonging to MemTensor, the company behind the MemOS operating system…
How We Got AD Admin In Red Teaming With GLM5.3 and RedactProxy
A client engaged us to red team their internal network. It was fully black box: zero input, no starting credentials, and no guidance on where to begin.…
BigCommerce Merchants Hit in Supply Chain Breach After Ribon App Credentials Were Stolen
BigCommerce has started alerting merchants that customer data was stolen from their stores after attackers got hold of API credentials belonging to Ribon,…
Arista Warns of Critical Actively Exploited VCO Vulnerability
Arista has published Security Advisory 0183 warning of a critical vulnerability in on-premises VeloCloud Orchestrator (VCO), tracked as CVE-2026-93952.…
