Cybersecurity

Breaches, CVE post-mortems, zero-day reporting and practical defense. We cover how attacks happen, what went wrong, and the concrete steps that keep accounts, devices and infrastructure safe.

SonicWall SMA1000 Zero-Day Chain Hits CVSS 10.0 [2026]

SonicWall confirmed on September 1, 2026 that attackers are actively exploiting two previously undisclosed vulnerabilities in its SMA 1000 Series appliances, the hardware and virtual gateways thousands of…
By Dr. Heinrich Vogel · Sep 22, 2026

CISA KEV Adds 12 CVEs as BOD 26-04 Cuts Deadline [2026]

The Cybersecurity and Infrastructure Security Agency added a fresh batch of actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog this week, and the update lands at an…
By Dr. Heinrich Vogel · Sep 3, 2026

Nexus Dark Web Service Sells 153M Driver Licenses [2026]

A dark web identity theft service calling itself Nexus is advertising more than 153 million scanned driver’s licenses from people across the United States and Canada, according to…
By Ryan Cole · Sep 22, 2026

Dropbox Breach Hits 5,000 Accounts via Lenovo ID [2026]

Dropbox confirmed on Tuesday, September 1, 2026, that roughly 5,000 user accounts were compromised in a security incident tied to a flawed identity integration with Lenovo. The disclosure,…
By Daniel Roth · Sep 2, 2026

Langflow RCE Hits CVSS 9.8, Rails Flaw Adds 9.5 [2026]

Two critical vulnerabilities in widely deployed developer tooling are now being exploited together in the same campaigns, according to research from VulnCheck cited by multiple outlets on September…
By Dr. Elena Marchetti · Sep 22, 2026

AI Cyberattacks Force Israel to Rethink Infrastructure [2026]

Israel’s national cyber authority is telling the country’s critical infrastructure operators to stop assuming they can keep attackers out. In a policy shift confirmed by The Jerusalem Post…
By Dr. Elena Marchetti · Sep 1, 2026

JFrog Artifactory Bug Hits CVSS 9.8, Not Yet in KEV [2026]

JFrog spent late August patching a hole in Artifactory that let an attacker with nothing more than network access walk in as an administrator. No password, no token,…
By Daniel Roth · Sep 22, 2026

Berlin Ransomware: 7-Day Gap Cost 5.79TB [2026]

Berlin’s state government spent a week connected to hackers before anyone pulled the plug. According to the announcement from Berlin authorities and reporting from outlets including Tech Times…
By Daniel Roth · Sep 22, 2026

Clop Ransomware Exploits PTC Windchill: 43 Victims [2026]

Clop’s ransomware leak site picked up dozens of new entries this month, and the common thread running through them is not a phishing email or a stolen password.…
By Dr. Elena Marchetti · Aug 31, 2026

PaperCut Zero-Days Hit CISA KEV, CVSS 9.4, 70K Orgs [2026]

The U.S. Cybersecurity and Infrastructure Security Agency added two PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog on August 31, 2026, confirming what security researchers had been…
By Ryan Cole · Aug 31, 2026

Latest news