Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
CVE-2026-17656 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware, attack groups, companies, products and services can be linked together on CybersecurityBoard.com.
CVE-2026-21858 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CVE-2026-34486 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CVE-2026-33824 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CVE-2026-17650 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Security researcher Håkon Måløy disclosed a prompt injection vulnerability in Microsoft 365 Copilot for Word that allows hidden instructions in a document…
AI SecurityCross-Prompt Injection AttackCVE-2026-50522Defender for Office 365
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, 2026, preventing…
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies to siphon funds…
A coordinated cyberattack targeting operational technology (OT) at over 30 community water systems in Minnesota occurred on July 26-27, 2026, prompting a…
The article discusses how AI models like Anthropic's Mythos are compressing exploit timelines, forcing a reevaluation of vulnerability management strategies. It argues…
AI SecurityAnthropicArtificial Intelligenceattack path prioritization
UNC5342, also known as Contagious Interview, is a North Korean-linked threat actor cluster that traditionally uses fake job interviews to deliver malware.…
The Chinese cybercrime group Silver Fox has been observed targeting a Japanese industrial manufacturing organization with a sophisticated attack chain that leverages…
Russian threat actors linked to the exploitation of a Zimbra vulnerability have been observed exploiting CVE-2026-42897, a cross-site scripting (XSS) flaw in…
A fake Chrome extension sideloaded by patching Chrome's Secure Preferences file, used to drain cryptocurrency wallets. Part of the DPRK malvertising campaign's…
A sophisticated JavaScript backdoor deployed via half-click exploits targeting Microsoft OWA, capable of persistent mailbox access, credential theft, and data exfiltration via…
Data ExfiltrationJavaScript implantMicrosoft OWAOWAReaper
The vulnerability CVE-2026-53264 was independently reported by Kyle Zeng (KyleBot) shortly before the TyphoonPwn 2026 competition. Lee Jia Jie later published a…
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
A vulnerability in Azure Cosmos DB's Gremlin query sandbox allowed code execution on a multi-tenant gateway, exposing a platform-wide signing key that…
Azure Service Fabric clusters hosted the multi-tenant DB Gateway component that was compromised in the CosmosEscape exploit chain. Customer databases were not…
Azure Service FabricCloud Infrastructuremulti-tenant
Microsoft Copilot stores user queries and conversation histories in Azure Cosmos DB, which were potentially accessible via the CosmosEscape vulnerability. No unauthorized…
AllSecure is a cybersecurity company that discovered and reported the DPRK-linked macOS malvertising campaign using fake updates to deliver crypto-stealing malware. CEO…
Check Point Software, a leading cybersecurity provider, announced the AI Network Firewall, the industry's first firewall designed to secure AI interactions at…
AI SecurityCheck PointCheck Point Softwarenetwork security
Zeon Corporation is a Japanese company involved in chemicals and software. Its legitimate binaries ConvertToPDF.exe and PDFDirect.exe were abused in DLL side-loading…
MNIT is the state agency responsible for coordinating the cybersecurity response to the coordinated cyberattack on Minnesota water systems, working with federal…
cybersecurity responseMinnesotaMNITstate government
The Python Package Index is the official repository for third-party Python packages, providing a platform for developers to publish and install software.…