- CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
- Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages
- North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware
- Why Organizations Are Turning to RPAM
- MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants
- Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan
- Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update
- ThreatsDay Bulletin: AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More Stories
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert
- Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets
- Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim 'Korean Leaks' Data Heist
- When Your $2M Security Detection Fails: Can your SOC Save You?
- Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps
- Webinar: Learn to Spot Risks and Patch Safely with Community-Maintained Tools
- RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware
