Vulnerability
-
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
By David Jones • Updated 18 hours ago -
CISA orders agencies to fix exploited Zimbra vulnerability
The collaboration software’s developer took almost a full month to patch the flaw after disclosing it.
By Eric Geller • Aug. 25, 2026 -
Explore the Trendline➔
Getty Images
TrendlineVulnerability Management
The rapid advancement Ai has changed the debate over secure software in the entrprise.
By Cybersecurity Dive staff -
Microsoft discloses maximum severity flaw in Entra ID
The company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.
By David Jones • Aug. 21, 2026 -
AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn
Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.
By David Jones • Updated Aug. 20, 2026 -
GitLab issues emergency patch for critical code-injection flaw
Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.
By David Jones • Updated Aug. 19, 2026 -
Deep Dive
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
The U.S. government’s promises about the Gold Eagle coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.
By Eric Geller • Aug. 18, 2026 -
Critical flaw in SAP Commerce Cloud faces initial exploitation attempts
The vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.
By David Jones • Updated Aug. 18, 2026 -
Cisco says software vulnerability could let hackers crash firewalls
Threat actors have already begun exploiting the flaw, according to the U.S. government.
By Eric Geller • Aug. 12, 2026 -
Deep Dive
CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’
The vulnerability coordination project has had a rocky few years, but a key leader says it will “flourish and improve.”
By Eric Geller • Aug. 11, 2026 -
Secure development can help turn the tables as AI alters cyber landscape
A top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software.
By David Jones • Aug. 10, 2026 -
Critical flaws allow hackers to exploit zero-touch provisioning process in TP-Link Omada
Attacks can cause widespread damage to trusted devices and data.
By David Jones • Aug. 7, 2026 -
Hackers grow more willing to destroy, not just disrupt, OT systems
Experts said the alarming trend has further stressed infrastructure providers that are already struggling with strong passwords, comprehensive logging and other basics.
By Eric Geller • Aug. 6, 2026 -
Microsoft launches agentic security platform designed to combat AI-based attacks
The rollout comes amid growing concerns about the ability of hackers to launch campaigns using autonomous methods.
By David Jones • July 28, 2026 -
Coca-Cola restores most production capacity at dairy unit after ransomware attack
The company said it does not expect the Fairlife disruption to have a material impact on financial performance or operations.
By David Jones • July 27, 2026 -
Zero-day flaw in Check Point SmartConsole is under exploitation
Researchers warned the vulnerability offers an attacker the ability to make key changes to security configurations.
By David Jones • July 24, 2026 -
The most vulnerable AI products are also some of the most commonly exposed online
It is becoming increasingly easy for hackers to target vulnerable AI tools on companies’ networks, even as those companies come to depend on them for more tasks.
By Eric Geller • July 24, 2026 -
Russia-backed threat actor targets Western organizations in phishing campaign
The threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information.
By David Jones • July 23, 2026 -
Microsoft SharePoint under attack via new exploit
Security researchers warn the potential risk could rival the widespread ToolShell campaign of 2025.
By David Jones • Updated July 23, 2026 -
Researchers trace SonicWall SMA1000 exploitation to late June
Multiple threat actors, including INC ransomware, have targeted vulnerable firewall systems.
By David Jones • July 20, 2026 -
CISA warns that multiple vulnerabilities in SharePoint are under exploitation
Security researchers say additional flaws are being chained together and a patch will not be available until August.
By David Jones • July 15, 2026 -
US authorities warn that state-linked hackers are targeting vulnerable networking devices
Hackers linked to Russian intelligence have exploited vulnerabilities in Cisco Smart Install devices.
By David Jones • July 13, 2026 -
Sponsored by HERE Enterprise Browser
Copy-paste might be the riskiest thing your enterprise employees do all day
This source of data leakage takes them less than a second and happens hundreds of times a day.
By Mazy Dar • July 13, 2026 -
Citrix via Flickr
Initial access broker linked to weaponization of CitrixBleed2 flaw
A similar pattern of exploitation was seen in prior attacks involving an open-source machine emulator.
By David Jones • July 10, 2026 -
Deep Dive
Sophisticated threat campaign pushes Cisco to the very edge
A monthslong exploitation wave against Cisco SD-WAN systems raises larger questions about trust and the insecurity of network infrastructure.
By David Jones • July 7, 2026 -
FortiBleed campaign traced to INC and Lynx ransomware operations
Researchers are also investigating the role of a suspected zero-day vulnerability.
By David Jones • July 2, 2026