Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
CVE-2026-32998 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware, attack groups, companies, products and services can be linked together on CybersecurityBoard.com.
CVE-2026-15920 is a moderate stored cross-site scripting vulnerability in Django's admin interface where unsafe URLField values could be rendered as links and…
CVE-2026-15830 is a moderate denial-of-service vulnerability in Django caused by deeply nested GEOMETRYCOLLECTION objects that can trigger a GEOS segmentation fault. The…
CVE-2026-15337 is a low-severity memory-consumption denial-of-service vulnerability in Django's check_for_language() function. The fix rejects language codes longer than 500 characters. Fixed in…
HashiCorp, Veeam, and the Django Software Foundation have released patches for 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and…
CVE-2026-16498 is a maximum-severity (CVSS 10.0) cross-tenant credential-reuse vulnerability in HashiCorp's Terraform MCP Server when running in stateless Streamable HTTP mode. The…
OpenAI has disrupted a Cambodia-based scam operation that leveraged its ChatGPT AI chatbot to facilitate a wide range of fraudulent schemes, including…
Cybersecurity researchers at Okta have uncovered a network of underground services selling discounted access to Anthropic's large language models (LLMs), including Opus…
Kali365, a device code phishing kit, is actively targeting US organizations by abusing Microsoft's legitimate authentication flow. According to ANY.RUN telemetry, the…
GitGuardian researchers have uncovered a significant security risk affecting n8n, a popular open-source workflow automation platform. By scanning public GitHub commits, they…
A cluster of 77 malicious extensions on the Open VSX marketplace has been discovered impersonating legitimate developer tools while exfiltrating sensitive information…
DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since June 2026. It uses ClickFix lures and steganographic PNG images to deliver malware…
INC Ransomware has emerged as the dominant threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN…
UNC6353 is a threat actor identified by Censys as potentially leveraging both DarkSword and Coruna exploit kits in attacks targeting Ukrainian entities.…
Microsoft Threat Intelligence has uncovered a macOS ClickFix operation that uses more than 250 front-end domains to distribute malware, including MacSync and…
Atomic Stealer (AMOS) is an infostealer malware targeting macOS, designed to steal credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files.…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
NullReceiver is a novel command-and-control (C2) technique that encodes the C2 server IP address within the recipient address of a zero-value Ethereum…
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
XProtect is Apple's built-in malware protection for macOS. It can trace commands pasted into terminal emulators, inspect process trees and network artifacts,…
macOS 26.4, released on March 24, 2026, includes protections against ClickFix-style attacks, such as a confirmation prompt for Terminal when pasting commands…
HashiCorp released Terraform MCP Server version 1.1.0 to address three vulnerabilities in the Streamable HTTP transport, including a CVSS 10.0 cross-tenant credential…
critical vulnerabilitiesHashiCorpTerraform MCP Server
The Django Software Foundation released versions 6.0.8 and 5.2.17 to patch four vulnerabilities, including a high-severity GeoDjango file write/RCE issue (CVE-2026-15307) and…
Cloudflare was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
MNIT is the state agency responsible for coordinating the cybersecurity response to the coordinated cyberattack on Minnesota water systems, working with federal…
cybersecurity responseMinnesotaMNITstate government