Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
Threat actors are actively exploiting a critical directory-traversal vulnerability in Broadcom's VMware vCenter, tracked as CVE-2026-59310 (CVSS 9.8), to gain persistent remote access to affected systems. The flaw, which allows remote code execution, was…
A critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (CVSS 9.1) allows an attacker with high privileges to execute arbitrary…
SAP has released patches for a maximum-severity vulnerability in Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary…
A maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) allows unauthenticated attackers to execute arbitrary code. The flaw, rated 10.0 on…
A critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (CVSS 9.9) allows a low-privileged attacker to submit crafted input, causing…
A critical out-of-bounds write vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform (CVSS 9.8) allows an unauthenticated attacker to…
OpenAI has launched GPT-5.6-Cyber, a specialized cybersecurity model designed for vulnerability research, penetration testing, and incident response. Built on the GPT-5.6 Sol…
Security researchers created a fictitious cryptocurrency startup and hired three individuals they believe were North Korean IT operatives, as part of an…
Researchers at the University of Birmingham and the security firm Fuzzware have discovered that a malicious SIM card can execute attacker-controlled code…
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
AI Coding AgentsAI SecurityAnthropicASSET Research Group
UNC6780 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse, is a security researcher who disclosed multiple Windows vulnerabilities, including CVE-2026-50656 (RoguePlanet),…
Kimwolf was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
GoReShell is a Windows backdoor used by the PurpleHaze threat cluster. It leverages functionalities from the reverse_ssh tool to establish reverse SSH…
reverse_ssh is an open-source tool used to establish SSH connections to threat actor-controlled infrastructure. It enables outbound connections, bypassing inbound security controls.…
Cybersecurity researchers have uncovered a new version of the Kimwolf/AISURU Android and IoT botnet, tracked as Kimwolf v7, which introduces significant enhancements…
Microsoft's August 2026 Patch Tuesday included patches for 421 security flaws, including 236 in Windows, and addressed critical vulnerabilities such as CVE-2026-50656,…
August 2026August 2026 Patch TuesdayMicrosoftPatch Tuesday
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
SAP Manufacturing Integration and Intelligence is impacted by two critical code injection vulnerabilities: CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS 9.1). These flaws…
code injectionCVE-2026-44758CVE-2026-44772SAP Manufacturing Integration and Intelligence
SAP Application Server ABAP for SAP NetWeaver and ABAP Platform is affected by CVE-2026-34265, an out-of-bounds write vulnerability that can be exploited…
ABAP PlatformCVE-2026-34265SAP Application Server ABAPSAP NetWeaver
SAP NetWeaver was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
ABAP Platform was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
QUIRSO is a German cybersecurity company that discovered active exploitation of CVE-2026-59310 during an incident response engagement. They identified 361 unique victim…
Deloitte was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Bugcrowd is a crowdsourced security platform that facilitated the disclosure of the RovoBlast vulnerability in Atlassian Rovo. The platform rated the issue…