Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. The flaws affect Apple macOS, Microsoft SharePoint, Broadcom…
CVE-2021-33044 is an authentication-bypass vulnerability in Dahua IP cameras and related products. Attackers can bypass device identity authentication by constructing malicious data…
CVE-2021-33045 is an authentication-bypass vulnerability in Dahua IP cameras. It involves a loopback login request using the 127.0.0.1 address. The flaw allows…
CVE-2024-39943 is an operating-system command-injection flaw in Rejetto HFS. It was associated with the recovered tooling in the Operation CameraSwarm campaign but…
CVE-2025-31702 is a privilege-escalation flaw in Dahua products that requires previously obtained normal-user credentials. It was associated with the recovered tooling in…
Phishing has evolved from malicious content (Phishing 1.0) to malicious intent (Phishing 2.0) and now to AI-powered, multi-channel attacks (Phishing 3.0). In…
Cybersecurity researchers at Hunt.io have disclosed a campaign, dubbed Operation CameraSwarm, that compromised more than 14,530 Dahua devices between June 17 and…
Researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads, dubbed "mind viruses," can spread between AI agents through editable system…
SafePal, a hardware wallet maker, has disclosed an authorization flaw in an order-tracking plug-in that exposed the personal information of approximately 39,798…
StopAndProtect is a cybercrime campaign that compromises WordPress sites to deliver a suite of malware, including ransomware, credential stealers, and worms. It…
ReliaQuest has uncovered a sophisticated JavaServer Pages (JSP) web shell deployed by the Clop ransomware group following the exploitation of CVE-2026-12569, a…
Active DirectoryClopcredential theftCVE-2021-27101
Settra was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Anubis was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
SilentDataCollector is a stealer component that exfiltrates file lists, specific files, and credentials. It includes a keylogger, WhatsApp data exfiltration, and screenshot…
SimpleChatProxy is a custom chat application used by attackers to communicate with victims during the StopAndProtect campaign, likely for negotiation or intimidation.
Researchers presented a survey of Ledger breach victims at USENIX Security '23, documenting spam, scams, phishing, and safety concerns following the 2020…
Microsoft's August 2026 Patch Tuesday included patches for 421 security flaws, including 236 in Windows, and addressed critical vulnerabilities such as CVE-2026-50656,…
August 2026August 2026 Patch TuesdayMicrosoftPatch Tuesday
ISO/IEC 27001:2022 is an international information security management standard. Its Annex A includes access control and identity management controls that organizations can…
This agent performs open-source reconnaissance on an organization to identify vulnerabilities and hardens detection before an attack occurs, simulating attacker behavior.
AIIRONSCALESIRONSCALES Red Teaming Agentpreemption
IRONSCALES is an email security company offering AI-driven products like Red Teaming Agent, Phishing SOC Agent, and Phishing Simulation Agent. Their Adaptive…
Osterman Research conducted a study commissioned by IRONSCALES, revealing that 88% of security leaders experienced incidents undermining trust in digital communications, and…