Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
cPanel has released a targeted security update to address a critical vulnerability that could allow authenticated hosting customers to execute SQL commands with database root privileges. The flaw, tracked as CVE-2026-58048 with a CVSS…
CVE-2026-58048 is a critical SQL injection vulnerability in cPanel & WHM and WP Squared, allowing authenticated hosting customers to execute arbitrary SQL…
CVE-2026-58047 is an HTTP request-smuggling vulnerability in cPanel's cpsrvd daemon. Under limited conditions, an unauthenticated remote attacker could manipulate responses delivered to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability affecting N-able N-central to its Known Exploited Vulnerabilities (KEV)…
CVE-2025-8875 is one of two N-able N-central vulnerabilities weaponized in limited attacks targeting on-premises environments approximately one year before CVE-2026-18577.
CVE-2025-8876 is the second N-able N-central vulnerability exploited in limited attacks on on-premises environments, highlighting recurring security issues in the RMM platform.
The cybersecurity industry has long assumed that offensive capability scales with technical expertise, ranking attackers from nation-state actors to script kiddies. However,…
Google has removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after researchers at Pillar Security demonstrated that…
Agent Development Kit (ADK)AI SecurityAntigravityCI/CD Security
Attackers compromised a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.…
DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since June 2026. It uses ClickFix lures and steganographic PNG images to deliver malware…
INC Ransomware has emerged as the dominant threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN…
UNC6353 is a threat actor identified by Censys as potentially leveraging both DarkSword and Coruna exploit kits in attacks targeting Ukrainian entities.…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Greatness is a commercial phishing-as-a-service (PhaaS) toolkit that has evolved to include device code phishing, AiTM token theft, and OAuth consent abuse.…
Cybersecurity researchers have uncovered an active, multi-wave campaign that uses social engineering lures themed around Adobe and Zoom updates, business document reviews,…
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
Powercat was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Xeno Executor was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Attackers in the SMOKE#SCREEN campaign used Cloudflare Quick Tunnel to expose a staging server temporarily, leveraging a service that is rarely monitored.…
The SMOKE#SCREEN campaign used a live WsgiDAV-based server to stage malicious payloads and maintain command-and-control over infected machines via a ScreenConnect relay…
RingCentral, a legitimate communication platform, has been impersonated in phishing campaigns that exploit safe sender exclusions. Attackers send spoofed voicemail lures that…
Monero Wallet was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Modrinth was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
SafePal was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Cloudflare was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
MNIT is the state agency responsible for coordinating the cybersecurity response to the coordinated cyberattack on Minnesota water systems, working with federal…
cybersecurity responseMinnesotaMNITstate government
The Python Package Index is the official repository for third-party Python packages, providing a platform for developers to publish and install software.…