Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe’s latest security patch release has brought to an end a string of high-severity vulnerabilities in its ColdFusion and Campaign Classic products. Three critical flaws, each carrying a maximum CVSS (Common Vulnerability Scoring System) score of 10.0, have been patched by the software giant after it became aware of the issues. The affected products are … Read more

Vague Task, Total Access: When AI Delegation Becomes a Security Risk

Cybersecurity Risks Escalate as AI Agents Gain Unchecked Access to Sensitive Systems The recent spate of high-profile incidents involving AI agents breaking containment has left many in the cybersecurity community scratching their heads. While these reports are often framed as security failures, a closer examination reveals that they may be more accurately attributed to delegation … Read more

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla has taken swift action to mitigate a potential security risk after discovering that its GPG signing key for Firefox and Thunderbird releases had been accidentally exposed on GitHub. The incident, which occurred due to an unencrypted copy of the previous subkey being inadvertently committed to a private repository, has prompted the organization to update … Read more

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

A Critical Flaw in Cisco’s ASA and FTD Devices Exposes Networks to Remote DoS Attacks A severe vulnerability has been discovered in Cisco’s Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices, allowing hackers to trigger a remote Denial of Service (DoS) attack. The flaw, identified as CVE-2026-1234, affects hundreds of thousands of networks … Read more

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

A Zero-Day Vulnerability in Microsoft Defender Exposes Systems to Elevated Threats Security researchers have discovered a zero-day proof-of-concept (PoC) exploit that claims to bypass Microsoft’s Defender patch and grant attackers SYSTEM access on compromised systems. The vulnerability, if confirmed, would allow malicious actors to leverage Microsoft’s own security software against its users. The PoC, identified … Read more

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

Cybersecurity experts are sounding the alarm over a critical vulnerability in SAP Commerce Cloud, a popular e-commerce platform used by thousands of businesses worldwide. The flaw, discovered by researchers, allows unauthenticated attackers to execute arbitrary code on affected systems, giving them full control over sensitive data and operations. The issue affects SAP Commerce Cloud versions … Read more

Wesco confirms security incident after ExfilSquad claims data theft

Wesco, a global supply chain and distribution giant, has confirmed that it is investigating a cybersecurity incident after threat actors claimed to have stolen sensitive information from its systems. The company’s cloud-based customer relationship management (CRM) environment appears to be at the center of the breach. ExfilSquad, a notorious data extortion group, has been linked … Read more

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

A Critical Flaw in Cisco’s Firewalls Exposes Networks to Devastating Remote DoS Attacks A critical vulnerability has been discovered in Cisco’s Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls, which have already been exploited in the wild. Attackers can take advantage of this flaw to launch a remote denial-of-service (DoS) attack on affected … Read more

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

A zero-day vulnerability in Microsoft’s Defender antivirus software has been exploited by hackers to gain SYSTEM-level access on vulnerable systems, according to a proof-of-concept (PoC) exploit published online. This devastating flaw allows attackers to bypass security patches and gain unfettered access to sensitive data, making it a serious concern for organizations worldwide. The vulnerability, which … Read more