Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
CVE-2026-33696 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware, attack groups, companies, products and services can be linked together on CybersecurityBoard.com.
CVE-2026-52813 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CVE-2026-52810 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CVE-2026-43774 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
A now-patched command injection vulnerability in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is under active exploitation in the wild, according…
The U.S. government has issued a joint advisory warning of an active threat targeting critical infrastructure organizations using AI-generated exploit scripts. The…
Researchers at the University of Massachusetts Amherst have demonstrated a novel attack, dubbed "Zombie Card," that can revive expired Visa contactless credit…
Cybersecurity researchers have disclosed two denial-of-service (DoS) attack techniques, collectively named "CDN Tsunami," that exploit how major content delivery networks (CDNs) convert…
Cybersecurity researchers have disclosed a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker…
GoldFactory is a Chinese-speaking threat actor linked to multiple Android and iOS banking malware families, including GoldDigger, GoldPickaxe, GoldDiggerPlus, and GoldKefu. The…
A newly uncovered cyber espionage operation dubbed SilkParasite has been targeting government bodies in Central Asia, according to a technical report from…
AI-assisted malwareBitdefenderBLOODALCHEMYCentral Asia
GoldPickaxe was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
GoldDiggerPlus was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
GoldKefu was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Cybersecurity researchers have uncovered significant updates to the Android banking trojans ToxicPanda (aka TgToxic) and GoldDigger, both of which now feature enhanced…
Researchers from UC Berkeley, the Ethereum Foundation, and NYU Shanghai presented a two-turn attack at USENIX Security 2026 that succeeded against Grok…
ISO/IEC 27001:2022 is an international information security management standard. Its Annex A includes access control and identity management controls that organizations can…
Israeli cybersecurity company Dream detailed a near-autonomous attack targeting government entities in Asia, reportedly Taiwan. The attack used AI agents like OpenClaw…
Mastercard's EMV contactless kernel (Kernel 2) includes a consistency check between the two expiry representations, causing a mismatch to be treated as…
American Express's EMV contactless kernel (Kernel 4) binds the expiration date into static data covered by offline data authentication, producing a hash…
Seven malicious Firefox extensions use threat actor-controlled Supabase projects to dynamically serve phishing or decoy content, abusing the platform's infrastructure.
The 37 sports-score shell extensions share a hard-coded credential for API-Sports, a legitimate sports data service, indicating coordinated infrastructure.