Microsoft Corrects Entra ID CVE-2026-69836 Exploit Claim
Microsoft corrected CVE-2026-69836 records to say the critical Entra ID flaw was not exploited and is fully mitigated with no customer action needed today.
Read more →Latest cybersecurity news, vulnerabilities, and threat intelligence
Microsoft corrected CVE-2026-69836 records to say the critical Entra ID flaw was not exploited and is fully mitigated with no customer action needed today.
Read more →
CISA warns attackers are exploiting critical MLflow SSRF flaw CVE-2026-64849, putting internal services and cloud metadata at risk worldwide. Patch now.
Read more →
Three Rust crates were poisoned to run credential-stealing malware during builds, exposing developer and CI systems before crates.io removed the releases.
Read more →
Exploitation attempts now target CVE-2026-58231, a CVSS 10 SAP Commerce Cloud flaw allowing unauthenticated remote code execution. Patch systems immediately.
Read more →
Attackers are exploiting VMware vCenter flaw CVE-2026-59310 to deploy reverse SSH access, with more than 360 victim IPs observed across 47 countries worldwide.
Read more →
Attackers are testing SharePoint CVE-2026-55040 after a public PoC exposed a critical authentication bypass. Microsoft patches are available right now.
Read more →
Zoom patched three annotation flaws that could enable remote code execution or denial of service across Workplace, Rooms, VDI and Meeting SDK clients.
Read more →
Storm-1175 is deploying new StormEncryptor ransomware as investigators assess a possible link to actively exploited N-able N-central security flaws today.
Read more →
OpenAI paused some Astra work after early tests could not rule out critical cyber capability, prompting stricter isolation, monitoring and external review.
Read more →
Metabase confirms active exploitation of a critical zero-day SQL injection flaw that gives remote attackers administrator access. Self-hosted users must patch.
Read more →