Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Cisco ISE: Patch Available for Directory Traversal CVE-2026-20148
A path traversal vulnerability in Cisco Identity Services Engine allows an authenticated remote attacker to read arbitrary files. A pa…

Private APN Emerges as New OT Attack Vector: Polish Cogeneration Plant Compromised
CERT Polska has documented the first real-world case of a private APN being used as an attack vector against operational technology. A…

Digital Garbage Hits the Cloud Core: Indiscriminate Scanning
SANS Dean of Research Johannes Ullrich documented widespread, untargeted scanning against the Cloud Metadata Service address 169.254.1…

SharePoint On-Prem Under Attack: Rapid7 PoC Weaponized Within 24 Hours
Threat actors are actively exploiting CVE-2026-55040 on Microsoft SharePoint on-premises servers using Rapid7's proof-of-concept code.…

GeoServer Zero-Day Under Fire: Hundreds of Exploit Attempts in Hours, Patches Released
A zero-day SQL injection in GeoServer was massively probed within hours of disclosure. The flaw is a regression of a 2023 vulnerabilit…

UNC6671: Personal Phones Become the Gateway to Steal SaaS Data
The UNC6671 group uses vishing on personal smartphones to bypass MFA and steal SaaS sessions. Google has tracked over $10 million in e…

NFV and 5G: The Paradox of European Digital Sovereignty
An intelligence report highlights systemic privilege-escalation vectors in European 5G SA networks. The MANO orchestration plane has b…

Interrupt Injection: MIT Attack Bypasses Spectre v2 Defenses on Intel and AMD
MIT CSAIL researchers Daniël Trujillo and Mengjia Yan presented the Interrupt Injection technique at Black Hat USA 2026, demonstrating…

Underground Markets Sell AI Tools to Orchestrate Ransomware Without Expertise
Trellix researchers have uncovered LLM-powered hacking tools for sale on underground forums that dramatically lower the technical barr…

Unisoc VoLTE Video-Call Exploit Chain Reaches Android Kernel — No Patch, No CVE
SSD Secure Disclosure details a two-stage exploit chain on Unisoc chipsets that starts with a malicious VoLTE video call and ends with…

Minnesota Under Attack: The Unpatchable CVE-2021-22681 Flaw
A coordinated cyberattack on July 26–27, 2026 struck more than 30 Minnesota water systems. The offensive exploited internet-exposed Ro…

RingCentral Breach Exposes 1.6 Million Records via Vishing Call
ShinyHunters compromised RingCentral with a single phone call, exposing 1.6 million records and leaking 280 GB of data. The real-time…