Security news.
Today's cybersecurity landscape is marked by widespread data breaches affecting millions of users and organizations, alongside ongoing exploitation of critical vulnerabilities. Ransomware operations continue to target major entities, while new research highlights the evolving capabilities of AI in both defense and offense.
Hackers Exploiting Unpatched GeoServer Zero-Day
An unpatched SQL injection vulnerability in GeoServer, allowing for potential remote code execution, is actively being exploited in the wild.
Citrix NetScaler Pre-Auth RCE Vulnerability (CVE-2026-8452)
A pre-authentication Remote Code Execution vulnerability has been identified in Citrix NetScaler, posing a critical threat to affected systems.
RingCentral Data Breach Exposes 1.6 Million Accounts
The ShinyHunters extortion group has claimed responsibility for a data breach at RingCentral, exposing personal information from 1.6 million accounts.
Over 1,000 Charities Hit by Beacon CRM Data Breach
A compromised AWS access key, exposed in publicly available JavaScript build artifacts, is believed to be the root cause of a data breach impacting over 1,000 charities using Beacon CRM.
Shell Investigates 'Potential Incident' After Clop Ransomware Claims
Oil giant Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data from the company.
Trivy, Not LiteLLM, Behind 2,500 Organization Compromise
New analysis indicates that the compromise of over 2,500 organizations, previously linked to malicious LiteLLM packages, was primarily due to Trivy, with most exposures occurring before the LiteLLM packages were published.
Apple Sends New 'Threat Notification' Alerts Over Mercenary Spyware Attacks
Apple has issued new threat notifications to users believed to be targeted by mercenary spyware attacks on their iPhones.
14,000 Trezor Customers Impacted by ShipMonk Data Breach
Shipping information, including names, addresses, emails, and phone numbers, for 14,000 Trezor customers was stolen in a data breach at fulfillment partner ShipMonk.