Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability affecting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. Tracked as CVE-2026-8037…
active exploitationBOD 26-04CISA KEVcommand injection
N-able has issued Hotfix 2 for its N-central Remote Monitoring and Management (RMM) product, responding to ongoing exploitation of a recently disclosed…
Metabase has disclosed a maximum-severity zero-day vulnerability in its business intelligence and data visualization software that is being actively exploited in the…
CVE-2023-38646 is a critical vulnerability in Metabase that allows pre-authenticated remote code execution on affected installations. With a CVSS score of 9.8,…
WordPress has released a critical security update to address a pre-authentication reflected cross-site scripting (XSS) vulnerability that affects all versions of the…
CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting vulnerability in WordPress's login screen. It allows unauthenticated attackers to execute arbitrary JavaScript in…
Cybersecurity researchers at Arctic Wolf Labs have uncovered a widespread email-driven phishing campaign that uses adversary-in-the-middle (AitM) techniques to compromise Microsoft 365…
AitM phishingArctic Wolf Labsbusiness email compromisecredential theft
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that exploits network address translation (NAT) connection state to hijack…
AppleBlack Hat USA 2026CVE-2026-50522CVE-2026-56181
Forescout has identified over 4,400 internet-facing Rockwell Automation programmable logic controllers (PLCs) worldwide, including 22 in cities affected by recent cyberattacks on…
Cordial Spider is CrowdStrike's tracking name for the umbrella collective behind UNC6671. The group conducts rapid data theft and extortion campaigns by…
Scattered LAPSUS$ Hunters (SLH) is a threat actor associated with shared phishing-kit infrastructure. Some vishing attempts have been linked to SLH tradecraft,…
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to the data extortion group…
Huntress researchers have uncovered a new ClickFix-style attack campaign targeting macOS users with a Go-based stealer malware capable of stealing cryptocurrency, browser…
Atomic Stealer is a macOS information stealer that has been observed in ClickFix campaigns using look-alike domains and server-side browser fingerprinting to…
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
Medium was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Fastmail was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Yahoo was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Bugcrowd is a crowdsourced security platform that facilitated the disclosure of the RovoBlast vulnerability in Atlassian Rovo. The platform rated the issue…
Cloudflare was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…