Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
This article reports active exploitation of CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. Attackers are actively exploiting the flaw, and organizations are urged to apply patches immediately and monitor for indicators of compromise.
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
This article provides a guide for managing identity source transitions for AWS IAM Identity Center. It outlines the steps to migrate from one identity source to another while maintaining security and minimizing disruption.
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.