Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
CVE-2024-6387 is a critical vulnerability in OpenSSH that was exploited by APT36 in their campaign targeting Afghan telecom and Indian critical infrastructure. The exploit was found on an exposed staging server, indicating the threat…
CVE-2020-9771 is a TCC bypass vulnerability in macOS Catalina that allows malware to access protected data without user consent. AmnesiaStealer exploits this…
Threat actors have begun exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS 9.1), following the public release of a proof-of-concept (PoC)…
A CVSS 9.6 incorrect authorization vulnerability in Adobe ColdFusion that could cause application denial-of-service. Fixed in versions 2025.0.12 and 2023.0.23.
A massive operation involving 737 free VPN and proxy extensions on the Chrome Web Store has been uncovered, primarily targeting Russian-speaking users…
1.1.1.1AdGuard VPNadversary-in-the-middleAI Sidebar with Deepseek, ChatGPT, Claude, and more
The Picus Blue Report 2026, based on over 338 million attack simulations in production environments, reveals a split in enterprise defense effectiveness.…
OpenAI has launched GPT-5.6-Cyber, a specialized cybersecurity model designed for vulnerability research, penetration testing, and incident response. Built on the GPT-5.6 Sol…
Security researchers created a fictitious cryptocurrency startup and hired three individuals they believe were North Korean IT operatives, as part of an…
APT36, also known as Transparent Tribe, is a Pakistan-aligned threat actor that has historically targeted government, military, and diplomatic organizations in India…
Transparent Tribe was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
North Korean IT workers are increasingly infiltrating government agencies and businesses by applying for remote jobs, passing interviews, and obtaining legitimate credentials.…
Afghan telecom providers and South Asian critical infrastructure organizations are the targets of a new campaign delivering a previously undocumented backdoor called…
PATCHCORD is a previously undocumented C/C++ backdoor delivered via fake VPN installers and telecom management tools. It establishes persistence by hijacking browser…
Microsoft's August 2026 Patch Tuesday included patches for 421 security flaws, including 236 in Windows, and addressed critical vulnerabilities such as CVE-2026-50656,…
August 2026August 2026 Patch TuesdayMicrosoftPatch Tuesday
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
Google Sheets is abused by SHEETCORD for command-and-control communications, allowing the threat actor to issue commands and exfiltrate data via a legitimate…
Chrome DevTools Protocol (CDP) is a protocol that allows tools to inspect and control Chromium-based browsers. AmnesiaStealer abuses CDP to gain interactive…
Afghan Telecom (AFTEL) is a state-owned telecommunications company in Afghanistan. Its internal Transport Management System (TMS) and VPN installers are impersonated in…
NorthScan, represented by Heiner García, contributed to the investigation by analyzing infrastructure and behavioral patterns of suspected DPRK operatives, helping to identify…
Lockheed Martin is a global defense and aerospace company. In the Operation Dream Job campaign, Lazarus Group impersonated recruiters from Lockheed Martin…
Bugcrowd is a crowdsourced security platform that facilitated the disclosure of the RovoBlast vulnerability in Atlassian Rovo. The platform rated the issue…