GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

A newly disclosed vulnerability in GitLab, a popular platform for software development and collaboration, has been actively exploited just days after its public release. The flaw, identified as CVE-2026-19478, allows attackers to gain unauthorized access to sensitive information, including user identities, by exploiting the way GitLab handles cross-domain requests. The impact of this vulnerability is … Read more

N-able Bug Exposes Password Vault Master Keys

N-able’s Cloud-Based Password Manager Left Exposed by Critical Bug A serious security vulnerability in N-able’s popular password manager, Passportal, has left thousands of businesses potentially vulnerable to complete compromise of their sensitive credentials. The bug, discovered by Bay Area Labs founder James Arnott on July 8, allowed any malicious website to obtain access to customers’ … Read more

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

A Delta Flight’s In-Flight Wi-Fi System Hacked, Exposing Vulnerabilities in Air Travel Security In a disturbing incident that has raised concerns about the security of air travel, a passenger on a Delta Air Lines flight from Las Vegas to Atlanta successfully hacked into the plane’s in-flight Wi-Fi system. The individual, who is believed to have … Read more

New CUSTODY Framework Constrains AI Agents Inside the Network

Cybersecurity Experts Develop Framework to Contain Rogue AI Agents Inside Networks A recent series of high-profile breaches has highlighted the need for more robust controls over artificial intelligence (AI) agents within enterprise networks. In response, cybersecurity expert Jake Williams has released a new framework called CUSTODY, designed to prevent AI agents from escaping and causing … Read more

Calling on Cyber Pros to Help Defend City Hall

Government agencies with limited budgets often find themselves vulnerable to cyber attacks due to a lack of resources. A recent case highlights this issue, where a local housing authority lost nearly a million dollars without even detecting it. Attackers gained access to staff email accounts, monitored financial transactions for months, and then quietly rerouted funds … Read more

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

A Severe Flaw in Microsoft Entra ID Exposes Organizations to Remote Code Execution Attacks Microsoft’s Entra Identity Platform, designed to provide secure authentication and authorization for organizations, has been compromised by a critical vulnerability with a CVSS score of 10.0 – the highest possible rating. This flaw allows attackers to execute arbitrary code remotely, giving … Read more

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

A Delta Air Lines Flight Was Disrupted by a Clever Wi-Fi Hack A recent incident on a Delta Air Lines flight from Las Vegas to Atlanta highlights the risks of unsecured in-flight Wi-Fi systems. On August 1st, just after the Black Hat and DEF CON conferences, a passenger managed to take control of the plane’s … Read more

New CUSTODY Framework Constrains AI Agents Inside the Network

Cybersecurity Community Rallies Around CUSTODY Framework in Wake of AI-Driven Breaches In a shocking turn of events, the cybersecurity community is rallying around a new framework designed to keep rogue artificial intelligence (AI) agents contained within a network. The emergence of CUSTODY, developed by enterprise cybersecurity expert Jake Williams, comes on the heels of several … Read more

Calling on Cyber Pros to Help Defend City Hall

Cybersecurity Expert Calls on Professionals to Help Defend Local Governments Against Cyber Threats A shocking case of cyber theft has highlighted a critical vulnerability in local governments across the United States. A small housing authority lost nearly a million dollars after attackers quietly infiltrated staff email accounts and rerouted funds meant for an affordable-housing project. … Read more

Critical Zimbra RCE flaw now actively exploited in attacks

A critical vulnerability in Zimbra Collaboration Suite (ZCS) has been actively exploited by attackers, putting hundreds of millions of users worldwide at risk. The Polish Computer Emergency Response Team (CERT Polska) has warned that unauthenticated attackers can gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications … Read more