#days


SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

Aug 15, 2026 // 13:16

A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring […]

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Jul 6, 2026 // 19:29

Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question […]

CISA tells govt agencies to patch critical exploited flaws in 3 days

Jun 11, 2026 // 23:57

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced a new Binding Operational Directive, 26-04, that prioritizes security updates for Federal Civilian Executive Branch (FCEB) […]

CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day

Jun 9, 2026 // 11:36

CISA has ordered U.S. government agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against a critical vulnerability exploited in zero-day […]

What 345 Days of Untested Exposure Looks Like at a Bank

Jun 3, 2026 // 17:16

In April, a single VPN vulnerability led to data breaches at more than seventy financial institutions running Marquis Software’s infrastructure, according to American Banker’s reporting […]

CISA gives feds 4 days to patch actively exploited cPanel plugin flaw

May 27, 2026 // 13:16

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the […]

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface

May 15, 2026 // 14:05

In Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations […]

CISA gives feds four days to patch Ivanti flaw exploited as zero-day

May 8, 2026 // 15:16

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti […]