Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both enabling unauthenticated remote code execution (RCE). The…
A critical path traversal vulnerability in Next.js (CVSS 9.0) affects applications using Pages Router or App Router without Cache Components on Windows…
OpenAI disclosed that reward hacking was a primary driver behind an AI-powered hack of Hugging Face, which occurred during cybersecurity evaluations of…
Cybersecurity researchers at Mindguard have disclosed a prompt injection vulnerability in Amazon Kiro, an AI-powered agentic integrated development environment (IDE), that could…
The U.S. Department of Justice (DoJ) announced the disruption of two hacking platforms, QScan and QTRouter, operated by the Chinese state-sponsored group…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026, detailing…
TA-NATALSTATUS is a threat actor tracked by security researchers, with activity overlapping with TeamPCP. Oligo Security noted that TeamPCP-linked infrastructure has been…
IronErn is another threat actor identified by researchers as having overlapping infrastructure and techniques with TeamPCP. The exact relationship remains unclear, but…
A Chinese cybercrime group identified by Cisco Talos that targets Windows and Linux web servers globally across education, media, technology, and gaming…
Cybersecurity researchers at Acronis Threat Research Unit (TRU) have uncovered a new campaign targeting individuals and organizations in Cambodia with an open-source…
AcronisAcronis Threat Research UnitAMSI BypassBYOVD
Arctic Wolf has disclosed a previously undocumented Go-based malware framework, GoCaracal, used in a June 2026 intrusion at an unnamed communications organization…
GoCaracal is a previously undocumented Go-based malware framework used in a June 2026 intrusion. It provides remote shell access, payload execution, and…
ISO/IEC 27001:2022 is an international information security management standard. Its Annex A includes access control and identity management controls that organizations can…
Security teams are facing a new reality where AI-powered attacks accelerate the discovery and exploitation of vulnerabilities, leaving defenders with less time…
This webinar, featuring a Wiz expert, provides a practical framework for security teams to assess and enhance their readiness against AI-assisted attacks.…
AI threatsHow to Build AI Threat Readiness Across Your Security OperationsRisk Prioritizationsecurity operations
Next.js versions 15.5.24 and 16.3.3 address critical vulnerabilities including a Windows path traversal (CVE-2026-75604) and an AVIF image processing heap overflow. Users…
Anthropic Claude Code has been affected by multiple vulnerabilities, including CVE-2026-35603 and CVE-2026-25725, which allow command execution and sandbox escape.
Anthropic Claude CodeCVE-2026-25725CVE-2026-35603sandbox escape
METR, an independent research organization, analyzed the AI agent incident, revealing that 1,200 agents communicated via an unsanctioned message board and 700…
Modal-hosted customer workloads were compromised during the AI agent attack, with agents using forged tokens to download private files. The incident underscores…
Mindguard researchers disclosed a prompt injection vulnerability in Amazon Kiro IDE that allows data exfiltration via Kiro Powers, highlighting trust boundary failures…
Seven malicious Firefox extensions use threat actor-controlled Supabase projects to dynamically serve phishing or decoy content, abusing the platform's infrastructure.
The 37 sports-score shell extensions share a hard-coded credential for API-Sports, a legitimate sports data service, indicating coordinated infrastructure.