Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The LevelBlue SpiderLabs Q2 2026 TTP Briefing highlights a surge in identity-based attacks, with stolen credentials outpacing defensive measures. Threat actors increasingly exploit weak authentication protocols and compromised identities to bypass traditional security controls, targeting organizations across finance, healthcare, and critical infrastructure.
filepath.Join was never designed to be a security boundary. We found two CSI drivers that shipped on the assumption it was, and the result was cross-tenant data access with optional node destruction, using nothing more than a valid Kubernetes manifest.
CISA published an advisory on vulnerabilities in Johnson Controls C-CURE 9000 and Victor application server used for physical access control. Exploitation could lead to authentication bypass and system compromise.
The UK's National Cyber Security Centre and international partners have issued a warning about a new zero-click phishing campaign. The campaign is attributed to the Russian state-sponsored cyber threat group known as LAUNDRY BEAR and targets Western organizations.
CISA released an advisory on vulnerabilities in Panduit IntraVUE, an industrial network management software. These vulnerabilities could allow unauthorized access and network disruption.
CISA added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-68686 affecting Fortinet FortiOS and CVE-2026-16812 affecting Arista VeloCloud, both with confirmed active exploitation.