Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The Blue Report 2026 shows that enterprise defenses are improving at the perimeter but are weak inside, with a post-compromise prevention rate of only 37%. While noisy actions like lateral movement are blocked, quiet actions like reconnaissance and credential theft often succeed, highlighting a need for better internal defenses.
Signal has rolled out Automatic Key Verification, a new security feature designed to protect users from man-in-the-middle attacks. The tool allows users to confirm that their encrypted conversations have not been intercepted or tampered with by malicious actors.
Adobe released updates for several critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. The most severe flaws include CVSS 10.0 issues that could lead to arbitrary code execution or privilege escalation, and Adobe recommends immediate patching.
Nightmare Eclipse publicly disclosed a Microsoft Defender zero-day named ShieldBreak after the August 2026 Patch Tuesday security updates. The exploit enables local attackers to escalate privileges to SYSTEM, bypassing Defender's protections.
Two malicious LiteLLM releases on PyPI in March 2026 contained credential-stealing code, potentially exposing over 2,500 organizations. CloudSEK obtained a dataset of captured files and log files from the campaign, but the data does not confirm actual victimization.
SAP addressed a maximum-severity vulnerability in Commerce Cloud that allows unauthenticated attackers to execute arbitrary code via specially crafted input. The flaw, rated CVSS 10.0, can fully compromise application confidentiality, integrity, and availability.