Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Iranian APTs Target U.S. PLCs: Unpatchable CVE-2021-22681 Exploited
Seven U.S. federal agencies confirmed an active Iranian APT campaign against Rockwell, Schneider, and Siemens PLCs. The critical CVE-2…

Dell RecoverPoint Zero-Day Exploited by UNC6201 Since 2024 for Root Access
CVE-2026-22769: Hardcoded credentials in Dell RecoverPoint for Virtual Machines gave UNC6201 root persistence, ghost NICs, and GrimBol…

June 2026 Patch Tuesday: Microsoft's Largest Ever, With Three Publicly Disclosed Zero-Days
Microsoft fixed nearly 200 vulnerabilities in the June 2026 Patch Tuesday, the most voluminous monthly cycle in the company's history.…

Cisco Confirms Active Exploitation of Hard-Coded Credentials in Secure Firewall Management Center
Cisco has confirmed active in-the-wild exploitation of CVE-2026-20316, a static credential vulnerability in Secure Firewall Management…

Chrome's Fifth 2026 Zero-Day: Google Issues Emergency Patch for Actively Exploited V8 Flaw
Google released an emergency update on June 8, 2026, for CVE-2026-11645, an out-of-bounds vulnerability in the V8 JavaScript engine al…

Swiss Federal SharePoint Breach Compromises 200 Accounts
The Federal Office for Information Technology and Telecommunication (BIT/FOITT) confirms exploitation of already-patched SharePoint fl…

Minnesota Cyberattack Hits Over 30 Water Systems; Cellular Modems Exposed PLCs
A coordinated cyberattack struck more than 30 Minnesota municipal water systems on July 26–27, 2026, forcing manual operations and tri…

DarkSword Exposes the Hidden iOS Exploit Market: Zero-Days in the Wild
DarkSword exploits six Apple vulnerabilities — three zero-days — to achieve full iPhone takeover. Three threat groups of differing geo…

WordPress: Backdoors in Essential Plugins, Supply Chain Collapses on Flippa
A buyer purchased 31 WordPress plugins on Flippa, injected PHP backdoors, and activated cloaked SEO spam for Googlebot after eight mon…

Zapscape: Hyunwoo Kim's Third KVM Escape Raises Systemic Security Questions
CVE-2026-64561 is a use-after-free in the KVM/x86 shadow MMU discovered by Hyunwoo Kim. It allows a kernel-privileged L1 guest to brea…

Amazon Attributes Four NPM Supply-Chain Attacks to North Korean Hackers
Amazon Threat Intelligence links the compromise of axios, debug, chalk, and typo-crypto to a North Korean group tracked as SAPPHIRE SL…

Lazarus Shares Zero-Day and C2 With Gunra: South Korea Raises Alarm
Four South Korean agencies confirm the Lazarus Group shared tools, infrastructure, and a zero-day vulnerability with the Gunra ransomw…