Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
A maximum-severity vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, is now being actively exploited in the wild, just days after SAP released a patch. The flaw, rated 10.0 on the CVSS scale, stems…
CVE-2025-31324 is a critical vulnerability in SAP NetWeaver that has been weaponized by China-nexus espionage clusters such as UNC5221, UNC5174, and CL-STA-0048,…
A critical authentication bypass vulnerability in Apple macOS Screen Sharing, tracked as CVE-2026-65400 (CVSS 9.8), is being actively exploited in the wild…
Threat actors are increasingly acquiring expired domains—known as "dropcatch domains"—to inherit their reputation and traffic, redirecting victims to scams and malware. According…
Cybersecurity researchers at CTM360 have exposed a large-scale, global recruitment-themed phishing campaign that leverages Browser-in-the-Browser (BitB) windows to steal Google and Facebook…
account takeoverAmazon Web ServicesAWS EC2Browser-in-the-Browser
Cybersecurity researchers at SpecterOps have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or…
BianLian is a cybercrime group that has been observed exploiting SAP vulnerabilities, including CVE-2025-31324, for ransomware and other malicious activities.
UNC5221 is a China-nexus espionage cluster that has been observed exploiting SAP vulnerabilities, including CVE-2025-31324, to compromise targets. The group is known…
NanoCore is a remote access trojan that has been identified in malware samples communicating with Sable Squirrel's infrastructure, highlighting its role in…
njRAT is a remote access trojan that has been detected in malware samples communicating with Sable Squirrel's infrastructure, contributing to the threat…
HiddenTear is a ransomware family whose signatures have been found in artifacts communicating with Sable Squirrel's infrastructure, indicating potential ransomware activity within…
Microsoft's August 2026 Patch Tuesday included patches for 421 security flaws, including 236 in Windows, and addressed critical vulnerabilities such as CVE-2026-50656,…
August 2026August 2026 Patch TuesdayMicrosoftPatch Tuesday
ISO/IEC 27001:2022 is an international information security management standard. Its Annex A includes access control and identity management controls that organizations can…
The Orchid Security platform operates in the identity observability category, discovering identities from applications and infrastructure, verifying how access is actually used,…
The Netherlands National Cyber Security Centre (NCSC-NL) is the national authority for cybersecurity in the Netherlands. It warned about active exploitation of…
DropCatch.com is a custom drop catching service that tracks domains approaching deletion and automatically attempts to register them on behalf of customers.…
Bugcrowd is a crowdsourced security platform that facilitated the disclosure of the RovoBlast vulnerability in Atlassian Rovo. The platform rated the issue…