Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Klue Breach: Dormant OAuth Credential Opens Multi-Victim Door to Salesforce
The Icarus extortion group exfiltrated CRM data from Klue customers by abusing stolen OAuth tokens. Cybersecurity vendor Huntress conf…

Apple Beats: Bluetooth Flaw Turns Headphones Into Spy Microphones
Apple patched CVE-2025-20701 in Beats Studio Buds: attackers within Bluetooth range could eavesdrop on conversations by exploiting a f…

Kodak Confirms Breach: ShinyHunters Threatens 2.2 Million Records
Kodak confirms a data breach after the ShinyHunters extortion group claimed theft of over 2.2 million records and threatened publicati…

Splunk Enterprise PostgreSQL Sidecar Bug (CVSS 9.8) Enables Unauthenticated RCE
CVE-2026-20253 allows unauthenticated remote code execution on Splunk Enterprise. The web proxy on port 8000 exposes an internal Postg…

MySQL Exposed at 26%: The 2026 Top 10 Attack Surface Exposures
Intruder's 2026 ASM Index reveals exposed databases and admin panels as primary vectors. Time-to-exploit has collapsed to a single day…

Malicious JetBrains Plugins Steal AI API Keys: 70,000 Downloads
A coordinated campaign of 15 malicious plugins on the JetBrains Marketplace exfiltrates AI API keys from developers' IDEs. Roughly 70,…

FortiSandbox: Three Critical Vulnerabilities Under Active Exploitation, Defused Cyber Says
Threat intelligence firm Defused Cyber observed active exploitation of three critical pre-authentication flaws in Fortinet FortiSandbo…

GhostTree: The NTFS Attack That Freezes EDR
Varonis Threat Labs disclosed GhostTree, an evasion technique that neutralizes Windows Defender using recursive NTFS junctions — no el…

Cisco SD-WAN, CVE-2026-20262: Internal Discovery, External Exploitation
Cisco disclosed CVE-2026-20262, a path traversal vulnerability in Catalyst SD-WAN Manager actively exploited in the wild. It requires…

iRhythm: Patient Health Data Stolen via Social Engineering
iRhythm Holdings disclosed a data breach in which attackers exfiltrated PHI and PII from third-party business applications through soc…

Chinese APT UNC6508: A Year of Espionage on REDCap Servers
Google exposes UNC6508: over a year of REDCap server compromise at U.S. and Canadian medical and military institutions using InfiniteR…

Infinite Campus: 137,123 Staff Emails Exposed in Salesforce Breach
ShinyHunters compromised an Infinite Campus employee's Salesforce account on March 18, 2026. After a failed extortion attempt, 137,123…