Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a July 2026 cybersecurity incident. The breach compromised names, Social Security numbers, medical information, and insurance details.
In this article Overview Technique Catalog Privilege Escalation Mitigation and protection guidance References Learn more Microsoft introduces the cloud web applications threat matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. Cloud-hosted web applications and serverless platforms create attack paths that can cross application code, managed runtimes, workload identities, deployment pipelines, and connected cloud resources.
CISA head says agency must change quickly to prevent the 'worst that could happen' The acting director of the Cybersecurity and Infrastructure Security Agency issued a sober warning Wednesday about the significant and possibly devastating cybersecurity vulnerabilities Americans face, blaming past government mistakes, outdated tech and AI as threats.
Analysis of the Project Glasswing vulnerability disclosure initiative shows a massive volume of CVEs being published, but only a small fraction are being actively analyzed or acted upon by vendors. Security researchers warn that the "mythos vulnerability firehose" is overwhelming defense teams and creating a human bottleneck.
Carnegie Mellon University CERT/CC warned that Skullcandy Dime 3 wireless earbuds expose users to Bluetooth hijacking attacks. The vulnerability allows nearby attackers to connect to the earbuds and inject audio, potentially delivering malicious commands or eavesdropping on the user.
SAP has addressed CVE-2026-44756, a maximum-severity memory corruption vulnerability in Extended Passport (EPP) Processing that could let a remote, unauthenticated attacker execute arbitrary operating system commands on vulnerable SAP systems. The issue, dubbed OVERPASS by Onapsis Research Labs, carries a CVSS score of 10.0 and resides in shared SAP kernel code used by multiple products and communication protocols.