Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
CISA added a critical command injection vulnerability in Progress Kemp LoadMaster to its KEV catalog after active exploitation, following over 792 exploitation attempts detected from 65 IPs across 18 countries. The flaw (CVE-2026-8037) enables unauthenticated remote code execution on vulnerable LoadMaster appliances.
This article from Unit 42 highlights that identity-based attacks drive 90% of incidents and explains how attackers exploit identities. It provides guidance for SOC leaders on improving their identity detection and response capabilities.
This article reports that AI chat bots are sending friend requests in League of Legends immediately after games end. It raises concerns about scammers using this tactic for malicious purposes.
A court ruling fined Meta $942 million and ordered the company to enhance its age assurance tools. The decision addresses harm caused to children on Meta's platforms.
This article details a critical SQL injection vulnerability in Metabase that was exploited in zero-day attacks. The attacks aimed to steal customer data, affecting systems like Framework and Tally.
This article celebrates the ten-year anniversary of AWS Managed Microsoft AD, which started as a solution for running directory-aware workloads in the cloud. It has since evolved to support enterprise identity for thousands of organizations worldwide.