Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
Apple paid a $150,000 bounty for a path traversal vulnerability in darwin-init, tracked as CVE-2026-20685, which could allow privileged network attackers to leak sensitive data from Private Cloud Compute.
A newly disclosed zero-day vulnerability in GeoServer is being actively exploited in the wild, according to threat intelligence firm watchTowr. The flaw,…
active exploitationCISA KEVCVE-2024-36401GeoServer
CVE-2024-6387 is a critical vulnerability in OpenSSH that was exploited by APT36 in their campaign targeting Afghan telecom and Indian critical infrastructure.…
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending…
CVE-2020-9771 is a TCC bypass vulnerability in macOS Catalina that allows malware to access protected data without user consent. AmnesiaStealer exploits this…
Threat actors have begun exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS 9.1), following the public release of a proof-of-concept (PoC)…
Cybersecurity researchers at CTM360 have exposed a large-scale, global recruitment-themed phishing campaign that leverages Browser-in-the-Browser (BitB) windows to steal Google and Facebook…
account takeoverAmazon Web ServicesAWS EC2Browser-in-the-Browser
Cybersecurity researchers at SpecterOps have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or…
This week's ThreatsDay Bulletin covers a wide range of cybersecurity developments, including new attack techniques, data breaches, and product updates. Key highlights…
A massive operation involving 737 free VPN and proxy extensions on the Chrome Web Store has been uncovered, primarily targeting Russian-speaking users…
1.1.1.1AdGuard VPNadversary-in-the-middleAI Sidebar with Deepseek, ChatGPT, Claude, and more
HoneyMyte was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Transnational Criminal Organizations (TCOs) are foreign groups that conduct cyber-enabled crimes such as ransomware, phishing, financial fraud, sextortion, and pig butchering scams…
The China-linked threat actor known as Jewelbug has been observed conducting cyber espionage against governments and militaries while simultaneously running a cryptocurrency…
Jewelbug is a China-based hackers-for-hire group that conducts cyber espionage against governments and militaries in the Middle East, Southeast Asia, and South…
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
CoolClient is a modular backdoor used by Mustang Panda. It supports keylogging, clipboard theft, credential harvesting, file management, and system reconnaissance. The…
msagent.sys is a signed Windows kernel-mode driver used by the latest CoolClient variant. It provides stealth by hiding processes, files, registry keys,…
Microsoft's August 2026 Patch Tuesday included patches for 421 security flaws, including 236 in Windows, and addressed critical vulnerabilities such as CVE-2026-50656,…
August 2026August 2026 Patch TuesdayMicrosoftPatch Tuesday
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
Lockdown Mode is an Apple security feature that provides an extreme level of protection against sophisticated cyberattacks, including mercenary spyware. Apple recommends…
CDP-Toolkit is a tool by SpecterOps that interacts with browsers via the Chrome DevTools Protocol. It supports cookie collection, browser data extraction,…
The RecruitTrap campaign also targets Facebook credentials through fake authentication popups, enabling account takeover and potential access to advertising platforms.
Bugcrowd is a crowdsourced security platform that facilitated the disclosure of the RovoBlast vulnerability in Atlassian Rovo. The platform rated the issue…