Mirage2FA Phishing Campaign Hits 4,500+ Companies, Bypassing Microsoft 365 MFA
A large-scale phishing campaign dubbed Mirage2FA has impacted over 4,500 organizations in the US and EU, abusing Microsoft 365 login flows to…
A large-scale phishing campaign dubbed Mirage2FA has impacted over 4,500 organizations in the US and EU, abusing Microsoft 365 login flows to…
A newly disclosed critical vulnerability in GitLab, tracked as CVE-2026-19478 (CVSS 9.4), is already being actively exploited in the wild, according to…
A now-patched command injection vulnerability in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is under active exploitation in the wild, according…
SAP has released patches for a maximum-severity vulnerability in Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary…
Akamai's State of the Internet: Enterprise AI Usage Risk Report 2026 reveals that top 5% of AI power users create outsized security…
Open source software is undergoing a forced maturation, driven by a convergence of threats and regulatory pressures. The article argues that while…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly patched critical vulnerability in JetBrains TeamCity to its Known Exploited…
The cybersecurity industry has long assumed that offensive capability scales with technical expertise, ranking attackers from nation-state actors to script kiddies. However,…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability affecting N-able N-central to its Known Exploited Vulnerabilities (KEV)…
The rapid evolution of AI is creating pressure on security leaders to adopt AI tools, but not all AI is suited for…