Global Intelligence Search
Query the entire database for vulnerabilities, news articles, open-source security tools, and known threat actors.
Exploited Zimbra Flaw Highlights Shrinking Window to Patch
Federal agencies have until the end of Monday to patch a bug in the Zimbra unified communications suite that allows unauthenticated remote code execution. The directive came after CISA added the vulnerability to its...
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
A newly discovered malware loader uses lists of ordinary English words to conceal and reconstruct malicious code, helping a rapidly growing infostealer evade detection before infecting victims. Researchers from Gen...
SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules
The Supreme Court dismissed one of two lawsuits blocking the Trump administration from implementing changes to U.S. Postal Service regulations regarding mail-in ballots, saying that states lacked standing because they...
CISA Warns of Exploited Oracle WebLogic Vulnerability
The cybersecurity agency CISA has instructed government organizations to immediately patch a critical vulnerability that has been widely exploited in attacks against Oracle WebLogic servers. The remote code execution...
Silent Patches Don’t Stop Attackers – They Blind Defenders
Every so often a vendor decides the smart move is to fix a vulnerability quietly. No advisory, no CVE, no explanation, just the vaguest handwave in a changelog. The logic sounds reasonable on its face: if you don’t...
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
Taiwanese prosecutors charged nine people Monday, including one from Nvidia and two from Super Micro , for illegally exporting “high-end AI servers” to mainland China, adding another wave of turbulence in the AI rivalry...
Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
This October, SecurityWeek, in partnership with MTSI, will offer the Cyber Attack Methods (CAM) course for the second consecutive year as part of the 25th Anniversary Industrial Control Systems (ICS) Cybersecurity...
First Malware Built Specifically for Car Head Units Fuels Botnet
Researchers at Kaspersky have come across what appears to be the first malware specifically designed for car head units, and have found links to the notorious BadBox botnet. The malware was discovered on an...
WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
Threat actors have been attempting to hack WordPress websites by exploiting two recently patched vulnerabilities affecting a MiniOrange plugin. The two vulnerabilities are CVE-2026-61979 and CVE-2026-15981, and they...
WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
Users can now add more than one passkey, which can be useful for those who use the application on both iOS and Android devices. As for two-step verification, the one-time passcode that was previously a six-digit PIN is...
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network...
Police arrests dozens of suspects in global cybercrime crackdown
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. The "Operation Jackal IV" international joint action...