Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography.
Cisco has released security updates for a critical vulnerability affecting selected Nexus 9000 Series switches that can allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
This article details an emergency Chrome security update addressing CVE-2026-85046, a type confusion vulnerability in the V8 engine that is actively exploited. The flaw enables remote code execution inside Chrome's sandbox via a crafted HTML page.
Russia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses.
Six hours. That's the incident notification window under the UAE's Information Assurance Standard v2.
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems.