Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
WordPress has released a critical security update to address a pre-authentication reflected cross-site scripting (XSS) vulnerability that affects all versions of the content management system. Tracked as CVE-2026-64638 with a CVSS score of 8.9,…
CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting vulnerability in WordPress's login screen. It allows unauthenticated attackers to execute arbitrary JavaScript in…
A use-after-free vulnerability in Linux's SCTP networking code, tracked as CVE-2026-64564 and named SCTPhantom, could allow local users to gain root privileges…
A use-after-free vulnerability in Linux's SCTP networking code, present since 2008, allows local users to gain root and potentially escape containers. Patched…
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack…
Black Hat USA 2026CVE-2026-50522CVE-2026-56181CVE-2026-63913
PortSwigger's AI-assisted research system, HTTP Terminator, has generated and proven new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. The system,…
Cybersecurity researchers at Arctic Wolf Labs have uncovered a widespread email-driven phishing campaign that uses adversary-in-the-middle (AitM) techniques to compromise Microsoft 365…
AitM phishingArctic Wolf Labsbusiness email compromisecredential theft
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that exploits network address translation (NAT) connection state to hijack…
AppleBlack Hat USA 2026CVE-2026-50522CVE-2026-56181
Forescout has identified over 4,400 internet-facing Rockwell Automation programmable logic controllers (PLCs) worldwide, including 22 in cities affected by recent cyberattacks on…
A new class of prompt injection attack, dubbed "AI Recommendation Poisoning," is spreading across commercial websites. It exploits pre-filled deep links in…
Cordial Spider is CrowdStrike's tracking name for the umbrella collective behind UNC6671. The group conducts rapid data theft and extortion campaigns by…
Scattered LAPSUS$ Hunters (SLH) is a threat actor associated with shared phishing-kit infrastructure. Some vishing attempts have been linked to SLH tradecraft,…
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to the data extortion group…
Huntress researchers have uncovered a new ClickFix-style attack campaign targeting macOS users with a Go-based stealer malware capable of stealing cryptocurrency, browser…
Atomic Stealer is a macOS information stealer that has been observed in ClickFix campaigns using look-alike domains and server-side browser fingerprinting to…
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
The Linux kernel's SCTP implementation contains a use-after-free flaw (CVE-2026-64564) that can be exploited for local privilege escalation and container escape. Patches…
The Stream Control Transmission Protocol (SCTP) in Linux has a use-after-free vulnerability in its dynamic address reconfiguration feature, leading to potential root…
DDoS-Guard was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Tucows was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Nicenic was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Cloudflare was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
MNIT is the state agency responsible for coordinating the cybersecurity response to the coordinated cyberattack on Minnesota water systems, working with federal…
cybersecurity responseMinnesotaMNITstate government