Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Multiple vulnerabilities have been discovered across VMware products including ESXi, vCenter, and Workstation, posing risks of remote code execution, denial of service, and information disclosure. A remote attacker could exploit these flaws to bypass security restrictions and compromise targeted systems.
Multiple vulnerabilities have been identified in Palo Alto Networks products, including PAN-OS, GlobalProtect, and cloud firewalls, which could allow remote attackers to execute code, escalate privileges, or manipulate data. The flaws impact a wide range of versions and platforms, from Android to Windows.
AWS Certificate Manager is discontinuing email-based domain validation for public certificates in line with CA/B Forum requirements. New email validation requests will be blocked starting March 31, 2027, and renewals will cease by September 30, 2027.
Ukrainian authorities dismantled 94 fraudulent call centers that lured victims into investment scams and attempted to gain access to bank accounts. The operation resulted in the seizure of millions of dollars in cash and equipment.
An Akira ransomware affiliate bypassed endpoint detection by restarting a compromised system into Safe Mode with Networking, disabling the EDR solution. While the attackers successfully exfiltrated data, the encryption phase of the ransomware attack ultimately failed.
A widespread threat campaign is actively exploiting a critical VMware vCenter vulnerability tracked as CVE-2026-59310. Security researchers warn that applying the patch may be insufficient, as attackers may have already established persistence or backdoors.