Critical vulnerabilities, active threats, and security news — curated for professionals.
Unpatched zero-day RCE — any authenticated user can achieve remote code execution via malicious branch name injection in git rebase
SourceActively exploited pre-auth API bypass delivering 'EKZ' credential stealer. Patch available (7.4.7+)
Source6 zero-day vulnerabilities disclosed without coordination — BlueHammer, RedSun, and UnDefend under active exploitation
SourceRussia-linked APT using ChatGPT/Gemini across all attack phases
SourceAndroid RAT with custom phishing builder ($700/mo)
SourceBanking trojan campaign targeting Iberian and Latin American banks
SourceNew credential stealer delivered via FortiClient EMS exploit
SourceMajor data breach at Carnival Corporation affecting approximately 6 million customers and employees
Read moreMassive investment in open-source supply chain security infrastructure
Read moreNew AI-powered platform for enterprise threat detection and response
Read moreFBI alert about phishing campaign targeting football fans ahead of 2026 World Cup
Read moreJoint operation by CrowdStrike, Google, and Shadowserver takes down major botnet command infrastructure
Read more