Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Active exploitation attempts are targeting a critical JWT bypass vulnerability in WSO2 API Manager that could allow attackers to forge authentication tokens and access protected API endpoints without valid credentials. The flaw allows unauthenticated attackers to bypass API Manager security controls and access sensitive API resources.
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
Microsoft's September 2026 Patch Tuesday haul includes 718 fixes for Windows along with numerous other product updates, representing a massive remediation effort despite security researchers noting it was actually a slow month relative to recent trends.
AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes.
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.