// 3 CRITICAL · 2 ZERO-DAY · 4 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSEC

Beacon CRM Breached, Robert Burns Trust Warns Donors: The Risk

A cyberattack on Beacon CRM, a SaaS provider for the non-profit sector, exposed contact data for over 1,000 organizations. The Robert…

Aug 31, 2026views - 1.2k

CYBERSEC

CareCloud Breach Exposes 3.75 Million Patient Records: The B2B Model Hides the Victims

CareCloud confirmed in March that an unauthorized actor accessed an AWS environment for six days, compromising 3,756,469 individuals.…

Aug 30, 2026views - 1.2k

aiEXPLOIT

AI Honeypot: Real Attacks on LiteLLM and MCP Servers Reveal Three Patterns

Wiz Threat Research deployed AI/ML honeypots for 90 days and documented sustained, service-specific attacks. Three distinct patterns t…

Aug 27, 2026views - 1.3k

CYBERSEC

VCS Blind Spot: Wiz CIRT Publishes DFIR Matrix for GitHub and GitLab

The Wiz CIRT DFIR poster maps VCS audit logs to MITRE ATT&CK but exposes critical gaps: 88% of customers use SaaS with 7-day retention…

Aug 27, 2026views - 1.1k

CYBERSEC

CareCloud Breach Balloons to 3.7 Million Victims: A Lesson in Regulatory Reporting Gaps

The CareCloud breach has surged from 350,000 to 3.75 million victims in five months, exposing how healthcare regulatory reporting can…

Aug 27, 2026views - 1.1k

VULNCVE

CVE-2026-4342: A Five-Day Window, Technical Debt With No Exit

The ingress-nginx vulnerability CVE-2026-4342 (CVSS 8.8) was patched in March 2026 but remains unapplied in thousands of clusters. The…

Aug 23, 2026views - 1.2k

CYBERSEC

Stripe: 1,033 Vendor API Keys Exposed, Satanic Claims ~20,000 Total

Threat actor Satanic published data from 669 Stripe vendors containing over 1,000 live API keys. Hudson Rock found no infostealer infe…

Aug 23, 2026views - 1.1k

malware

HollowGraph: APT Malware Turns M365 Calendars into Covert C2 Channel

HollowGraph exploits the Microsoft Graph API to transform compromised account calendars into bidirectional command-and-control channel…

Aug 22, 2026views - 1.1k

CYBERSECCVE

Microsoft Corrects Course: CVE-2026-69836 Was CVSS 10, But Not Exploited

Microsoft reclassified CVE-2026-69836, a critical Entra ID flaw, retracting its initial claim of active exploitation. The episode rais…

Aug 22, 2026views - 1k

CYBERSECCVE

CVE-2024-9042: SYSTEM-Level RCE on Kubernetes Windows Nodes via a Single curl Request

A vulnerability in Kubernetes' Log Query feature enables remote code execution with SYSTEM privileges on every Windows node in a clust…

Aug 22, 2026views - 1k

CYBERSECEXPLOIT

Digital Garbage Hits the Cloud Core: Indiscriminate Scanning

SANS Dean of Research Johannes Ullrich documented widespread, untargeted scanning against the Cloud Metadata Service address 169.254.1…

Aug 19, 2026views - 1.2k

CYBERSEC

NFV and 5G: The Paradox of European Digital Sovereignty

An intelligence report highlights systemic privilege-escalation vectors in European 5G SA networks. The MANO orchestration plane has b…

Aug 19, 2026views - 1.2k