Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
Google has patched a record 1,442 security vulnerabilities across Chrome versions 149, 150, and 151, surpassing the total number of flaws fixed in the previous 23 milestones combined. The latest Chrome 151 update alone…
Researchers from Singapore's Nanyang Technological University have disclosed a widespread class of security vulnerabilities affecting 4G and 5G core networks. The study,…
CVE-2026-8233 is a session hijacking vulnerability discovered in Dotouch's XproUPF, a 5G core network User Plane Function. The flaw allows an attacker…
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the…
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to…
Cybersecurity firm Bitsight has uncovered a large-scale operation dubbed 'Fuyao' involving cheap Android TV boxes that secretly impersonate smartphones to commit ad…
Security researcher Håkon Måløy disclosed a prompt injection vulnerability in Microsoft 365 Copilot for Word that allows hidden instructions in a document…
AI SecurityCross-Prompt Injection AttackCVE-2026-50522Defender for Office 365
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, 2026, preventing…
A suspected Chinese-speaking threat actor has been conducting a series of cyber attacks against government organizations in Central Asia since January 2025.…
SilentRaid, also known as MystRodX or TrustFall, is a C++-based implant linked to previous attacks. Kaspersky found infrastructure overlaps between this campaign…
The vulnerability CVE-2026-53264 was independently reported by Kyle Zeng (KyleBot) shortly before the TyphoonPwn 2026 competition. Lee Jia Jie later published a…
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
Cheap Android TV boxes, particularly models like H96_MAX_V11, are the primary devices affected by the Fuyao operation. They are shipped with malicious…
Push Security provides an AI-native browser security platform that detects and stops advanced browser-based attacks, including device code phishing. Their agentic threat…
Researchers from Singapore's Nanyang Technological University conducted a study that identified 84 vulnerabilities in 4G and 5G core networks, including a session…
4G Security5G SecurityiFinderNanyang Technological University
MNIT is the state agency responsible for coordinating the cybersecurity response to the coordinated cyberattack on Minnesota water systems, working with federal…
cybersecurity responseMinnesotaMNITstate government
The Python Package Index is the official repository for third-party Python packages, providing a platform for developers to publish and install software.…