Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

KDDI Breach Exposes 14.2 Million Credentials Across Six Japanese ISPs
KDDI Corporation disclosed unauthorized access to a shared email platform serving six Japanese telecom operators on June 17, 2026. The…

ATEN Unizon: Authenticated Bug Deletes Files, CVSS 5.5 Understates Risk
Directory traversal in ATEN Unizon's uploadSSL lets an authenticated attacker delete arbitrary files. The CVSS 5.5 rating masks real o…

ZDI-26-393: Stack Buffer Overflow in X.Org Server XKB Subsystem Enables Local Root Escalation
The Zero Day Initiative disclosed ZDI-26-393 on June 24, 2026, detailing a local privilege escalation vulnerability in X.Org Server. A…

SBU and FBI Expose Russian Social-Engineering Campaign Targeting Signal and WhatsApp Accounts
Ukraine's SBU and the FBI disclosed a long-running Russian operation that uses morning-timed SMS phishing to steal verification codes…

Klue Supply Chain Compromised, Icarus Hacked, Data in Circulation
The Klue-Salesforce supply chain breach now spans roughly two dozen confirmed victims. The extortion group Icarus, which claimed respo…

Miasma: The Malware Turning npm Into a Developer Trap
Miasma compromised 109 npm packages and GitHub Actions using Phantom Gyp and the Bun runtime. It extracts CI/CD secrets from memory an…

SharkLoader: The Malware That Bypasses Loader Lock to Hide Cobalt Strike
Kaspersky has identified SharkLoader, a new loader that exploits Perfect DLL Hijacking to bypass Windows Loader Lock and deploy Cobalt…

CL-STA-1062: From Taiwanese Web Hosting to Power Plants with TinyRCT Backdoor
Unit 42 reveals CL-STA-1062's escalation: from web hosting to state energy infrastructure in Southeast Asia with a custom .NET backdoo…

Turla's STOCKSTAY Backdoor Has Targeted Ukraine Since 2022
Google Threat Intelligence Group disclosed STOCKSTAY, a multi-component backdoor from the Turla APT active since December 2022 against…

Linux Foundation Launches Akrites: A Shared SIRT for Open Source Software
Akrites brings 19 tech giants under one shared SIRT for open source vulnerabilities. A 5% patch rate and Dolan's admission: the road a…

PTC Windchill: First In-the-Wild Exploitation of a PLM System
CVE-2026-12569 is the first PTC vulnerability added to the CISA KEV catalog. Active exploitation with persistent JSP webshells, patche…

Burnyard: Local Malware Analysis Beats Cloud on Speed, But Accuracy Remains Unverified
Ohio State University's Burnyard project challenges VirusTotal and Sophos Intelix with user-space emulation on local hardware, deliver…