Latest news

  1. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-87701 Azure Cosmos DB Elevation of Privilege Vulnerability

    Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges…

  2. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-70200 Azure Logic Apps Elevation of Privilege Vulnerability

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

  3. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability

    Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

  4. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-85917 Azure AI Foundry Elevation of Privilege Vulnerability

    Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

  5. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69671 Microsoft Office Word Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  6. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69678 Microsoft Office PowerPoint Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  7. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69686 Microsoft Office Word Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  8. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69722 Microsoft Office Word Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  9. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69734 Microsoft Office Word Information Disclosure Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  10. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69724 Microsoft Office SharePoint Remote Code Execution Vulnerability

    Updated an acknowledgement. This is an informational change only.

  11. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69719 Microsoft Office Word Information Disclosure Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  12. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69739 Microsoft Office Information Disclosure Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  13. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69759 Microsoft Office Word Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  14. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69767 Microsoft Office PowerPoint Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  15. via Infosecurity Magazine

    CISA Urges Critical Infrastructure to Plant Decoys Inside Networks

    CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks

  16. Vulnerabilities via Qualys

    CISA Warns of Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)

    Cisco released security updates to address a critical severity vulnerability in Cisco Identity Services Engine. Tracked as CVE-2026-76460, successful exploitation of the…

  17. Threat Intel via CyberScoop

    Authorities seize popular, long-running DDoS-for-hire service domains

    Authorities seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service…

  18. Breaches via Help Net Security

    Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

    Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in…

  19. Threat Intel via Kaspersky Securelist

    The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

    Introduction Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has…

  20. Breaches via Bishop Fox

    MikroTrick: Inside the RouterOS Takeover Chain

    Attackers were exploiting MikroTik routers before fixes went public. Bishop Fox reproduced the full unauthenticated takeover chain, found persistence artifacts on real…