Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
Security firms ThreatBook and Imperva report active exploitation of a critical remote code execution vulnerability in Alibaba's Fastjson 1.x JSON library for Java, tracked as CVE-2026-16723. The flaw, assigned a CVSS score of 9.0…
A critical remote code execution vulnerability in Alibaba's Fastjson 1.x JSON library for Java, affecting versions 1.2.68 through 1.2.83. The flaw allows…
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit for a remote code execution (RCE) vulnerability in self-managed…
CVE-2026-54121 is a critical vulnerability in Microsoft's Active Directory Certificate Services (AD CS) that allows low-privileged users to impersonate a Domain Controller.…
AD CSCVE-2026-54121Improper AuthorizationMicrosoft
CTM360 Research has uncovered a sophisticated evolution in insurance phishing campaigns, where attackers now hijack accounts in real time rather than harvesting…
An attacker installed the open-source Hermes AI assistant on a rented server, disabled its permission-requesting YOLO mode, and directed it at Thailand's…
AI-assisted attackApacheBob DiachenkoChinese-speaking threat actor
Most organizations focus on protecting Non-Human Identities (NHIs) from theft, but a more insidious threat is emerging: fabricated machine identities. Unlike stolen…
Active DirectoryAgentic AIAI SecurityCloud Security
Cybersecurity researchers have uncovered a large-scale campaign that weaponizes compromised GitHub repositories to target cPanel and WebHost Manager (WHM) instances. The activity…
GangExposed is a mysterious whistleblower who publicly doxxed DevMan operator identities in June 2025, causing some affiliates to abandon the operation. DevMan…
The operators of the DevMan ransomware-as-a-service (RaaS) scheme maintain a dedicated web platform that offers affiliates the ability to build payloads, oversee…
A malvertising operation named SourTrade, active since late 2024, uses victims' browsers to build a Windows executable from components served across multiple…
JSCEAL is a stealer malware tracked by Check Point, identified by Bitdefender in a September 2025 malvertising campaign targeting TradingView users. It…
WeevilProxy is the name used by WithSecure for the stealer malware that Bitdefender identified in a September 2025 malvertising campaign targeting TradingView.…
Variant.DenoSnoop.Marte.1 is a loader detection name used by Bitdefender in a September 2025 report on a TradingView malvertising campaign. Confiant's July 2026…
The Bit2Watt attack paper was accepted to CHES 2026, the IACR's hardware-security conference, highlighting the threat of GPU-based power grid destabilization.
Operation Aquila was an 18-month investigation by Australia's signals directorate and federal police that identified Aleksandr Gennadievich Ermakov as the perpetrator behind…
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
StreamSaver.js is an open-source streamed-download library that was used in earlier SourTrade activity tracked through April 30, 2026. The current campaign retains…
Fastjson is a high-performance JSON library for Java developed by Alibaba. Versions 1.2.68 through 1.2.83 are affected by CVE-2026-16723. Fastjson2 is not…
Spring Boot is a popular Java framework used for building microservices and web applications. The CVE-2026-16723 exploit requires a Spring Boot executable…
Confiant, a cybersecurity firm, detailed the SourTrade malvertising campaign on July 23, 2026. The campaign uses victims' browsers to assemble malware executables…
WithSecure is a cybersecurity company that tracks the stealer malware identified in the TradingView malvertising campaign as WeevilProxy. The same malware is…
ThreatBook is a cybersecurity firm that detected in-the-wild exploitation of CVE-2026-16723 starting July 22, 2026. It added detection support two days prior.
A VPN service provider sanctioned by the U.S. Treasury for enabling ransomware actors and cybercriminals to obscure their origins. Operational since 2014,…