Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

CVE-2026-18963: Keycloak Account Takeover in Seconds, Bypassing MFA
A critical flaw in Keycloak's password-reset flow lets an unauthenticated attacker seize any account — including admins — in roughly f…

AMD Confirms Two TPM 2.0 Flaws: False Attestations on Ryzen from 3000 Series to AI
Two vulnerabilities in AMD's TPM 2.0 firmware jeopardize the hardware attestation chain on Ryzen processors. Patched firmware has been…

ShinyHunters Hits 100+ Universities with Oracle Zero-Day CVSS 9.8
The ShinyHunters group exploited CVE-2026-35273, an unauthenticated RCE in Oracle PeopleSoft, against more than 100 organizations befo…

CVE-2026-18294: RCE in OriginLab Origin Viewer via Malformed OGW File
The CVE-2026-18294 vulnerability in OriginLab Origin Viewer's OGW parser enables remote code execution with a CVSS 7.8 score. Exploita…

Parallels RAS Client: Local Vulnerability Allows Escalation to SYSTEM
CVE-2026-18263 affects the RAS RDP Backend Service with a CVSS 7.8 score. An exposed dangerous function allows low-privilege code to e…

TeamPCP Exploits AI Supply Chain to Steal One Terabyte of Credentials
The TeamPCP campaign compromised GitHub Actions and PyPI packages between March and April 2026. Over 2,500 organizations potentially e…

Exploitarium: The 'Recruitment by Chaos' That Shatters the CVD Model
Pseudonymous researcher 'bikini' dumped over 30 zero-day PoC exploits on GitHub on June 27, 2026, without any vendor coordination. CVE…

Medusa Tops 500 Victims: CISA Updates Advisory on 24-Hour Exploit Window
CISA, FBI, and HHS updated advisory AA25-071A on August 18, 2026, documenting over 500 Medusa ransomware victims since June 2021, with…

CISA Adds CVE-2025-62593 to KEV Catalog: Ray at Risk of RCE
CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17, 2026. The critical flaw in the Ray framework ex…

SilkParasite Exposes the Line Between AI-Assisted and AI-Generated Malware
Bitdefender uncovered SilkParasite, a cyber-espionage campaign using seven RAT families and AI-assisted development to target governme…

Trivy and LiteLLM Compromised: 2,100+ Organizations Exposed via Security Tools
TeamPCP compromised the CI/CD pipelines of Trivy and LiteLLM between March 19 and March 24, 2026. Six confirmed breaches hit European…

The Blackout That Wasn't: When PLC Doubt Shuts Down a Power Plant
An alleged four-day shutdown at an unnamed UK power plant remains officially unconfirmed as of August 23, 2026. The original source, d…