Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Heights Finance Holdings disclosed a data breach after an unauthorized party accessed a third-party cloud platform containing sensitive customer data, including personal, banking, and identity information. The consumer lender filed a report with Texas regulators mentioning up to 734,828 affected individuals, though this figure covers operations across multiple states including Alabama, Tennessee, Georgia, Texas, and South Carolina.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
Microsoft confirmed an outage affecting search functionality in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. Some users experienced issues searching for emails, files, and other content across these services during the disruption.
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker confirmed that all affected customers were notified individually by email on August 16, 2026.
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads.