Latest news
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-87701 Azure Cosmos DB Elevation of Privilege Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-70200 Azure Logic Apps Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-85917 Azure AI Foundry Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69671 Microsoft Office Word Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69678 Microsoft Office PowerPoint Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69686 Microsoft Office Word Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69722 Microsoft Office Word Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69734 Microsoft Office Word Information Disclosure Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69724 Microsoft Office SharePoint Remote Code Execution Vulnerability
Updated an acknowledgement. This is an informational change only.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69719 Microsoft Office Word Information Disclosure Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69739 Microsoft Office Information Disclosure Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69759 Microsoft Office Word Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69767 Microsoft Office PowerPoint Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
via Infosecurity Magazine
CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks
-
Vulnerabilities via Qualys
CISA Warns of Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)
Cisco released security updates to address a critical severity vulnerability in Cisco Identity Services Engine. Tracked as CVE-2026-76460, successful exploitation of the…
-
Threat Intel via CyberScoop
Authorities seize popular, long-running DDoS-for-hire service domains
Authorities seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service…
-
Breaches via Help Net Security
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in…
-
Threat Intel via Kaspersky Securelist
The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
Introduction Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has…
-
Breaches via Bishop Fox
MikroTrick: Inside the RouterOS Takeover Chain
Attackers were exploiting MikroTik routers before fixes went public. Bishop Fox reproduced the full unauthenticated takeover chain, found persistence artifacts on real…
