Vulnerability


  • Microsoft building with logo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Researchers warn about chained SharePoint sequence

    An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks. 

    By Updated 18 hours ago
  • A hand holds a magnifying glass up to a red exclamation point enclosed by a red triangle
    Image attribution tooltip
    tadamichi via Getty Images
    Image attribution tooltip

    CISA orders agencies to fix exploited Zimbra vulnerability

    The collaboration software’s developer took almost a full month to patch the flaw after disclosing it.

    By Aug. 25, 2026
  • Trendline

    Vulnerability Management

    The rapid advancement Ai has changed the debate over secure software in the entrprise.

    By Cybersecurity Dive staff
  • Microsoft building exterior
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Microsoft discloses maximum severity flaw in Entra ID

    The company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.

    By Aug. 21, 2026
  • Siemens flags fly in front of Siemens AG headquarters in Berlin, Germany, on Aug. 20, 2024.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn

    Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.

    By Updated Aug. 20, 2026
  • a software developer inspects code on a screen
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    GitLab issues emergency patch for critical code-injection flaw

    Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.

    By Updated Aug. 19, 2026
  • A man stands at a lectern near signs that read "Winning the AI race"
    Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip
    Deep Dive

    AI-powered vulnerability clearinghouse faces deep skepticism, major challenges

    The U.S. government’s promises about the Gold Eagle coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.

    By Aug. 18, 2026
  • SAP office exterior.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Critical flaw in SAP Commerce Cloud faces initial exploitation attempts

    The vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.

    By Updated Aug. 18, 2026
  • A large sign says "Cisco" in red letters. The sign sits on a grassy lawn in front of a building with many windows.
    Image attribution tooltip
    Sundry Photography via Getty Images
    Image attribution tooltip

    Cisco says software vulnerability could let hackers crash firewalls

    Threat actors have already begun exploiting the flaw, according to the U.S. government.

    By Aug. 12, 2026
  • A digital depiction of a red triangle sign with an exclamation point in the center with binary code in the background.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip
    Deep Dive

    CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’

    The vulnerability coordination project has had a rocky few years, but a key leader says it will “flourish and improve.”

    By Aug. 11, 2026
  • David Weston, CVP, AI Security at Microsoft, delivers a keynote address during the 2026 Black Hat USA conference in Las Vegas.
    Image attribution tooltip
    Permission granted by Black Hat USA
    Image attribution tooltip

    Secure development can help turn the tables as AI alters cyber landscape

    A top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software.

    By Aug. 10, 2026
  • Forescout - Vedere Labs presented research at the Black Hat USA conference about vulnerabilities in TP-Link Omada that could allow attackers to abuse zero-touch provisioning technology.
    Image attribution tooltip
    Permission granted by David Jones
    Image attribution tooltip

    Critical flaws allow hackers to exploit zero-touch provisioning process in TP-Link Omada

    Attacks can cause widespread damage to trusted devices and data. 

    By Aug. 7, 2026
  • A man speaks while a woman and a man on either side of him listen to him
    Image attribution tooltip
    Eric Geller/Cybersecurity Dive
    Image attribution tooltip

    Hackers grow more willing to destroy, not just disrupt, OT systems

    Experts said the alarming trend has further stressed infrastructure providers that are already struggling with strong passwords, comprehensive logging and other basics.

    By Aug. 6, 2026
  • Microsoft building exterior
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Microsoft launches agentic security platform designed to combat AI-based attacks

    The rollout comes amid growing concerns about the ability of hackers to launch campaigns using autonomous methods. 

    By July 28, 2026
  • fairlife, coca-cola
    Image attribution tooltip
    Courtesy of Coca-Cola
    Image attribution tooltip

    Coca-Cola restores most production capacity at dairy unit after ransomware attack

    The company said it does not expect the Fairlife disruption to have a material impact on financial performance or operations. 

    By July 27, 2026
  • New generation internet technologies and security bug.
    Image attribution tooltip
    Devrimb
    Image attribution tooltip

    Zero-day flaw in Check Point SmartConsole is under exploitation

    Researchers warned the vulnerability offers an attacker the ability to make key changes to security configurations.

    By July 24, 2026
  • Industrial control equipment, including programmable logic controllers, are seen mounted to a wall
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    The most vulnerable AI products are also some of the most commonly exposed online

    It is becoming increasingly easy for hackers to target vulnerable AI tools on companies’ networks, even as those companies come to depend on them for more tasks.

    By July 24, 2026
  • A man pushes his bike through debris and destroyed Russian military vehicles on a street on April 06, 2022 in Bucha, Ukraine.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Russia-backed threat actor targets Western organizations in phishing campaign

    The threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information.

    By July 23, 2026
  • The Microsoft logo is pictures on the technology company's headquarters in Redmond, Washington, on July 3, 2024.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Microsoft SharePoint under attack via new exploit

    Security researchers warn the potential risk could rival the widespread ToolShell campaign of 2025.

    By Updated July 23, 2026
  • A sign in front of a modern office building with the SonicWall logo on it.
    Image attribution tooltip
    Permission granted by SonicWall
    Image attribution tooltip

    Researchers trace SonicWall SMA1000 exploitation to late June

    Multiple threat actors, including INC ransomware, have targeted vulnerable firewall systems.

    By July 20, 2026
  • Microsoft building exterior
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    CISA warns that multiple vulnerabilities in SharePoint are under exploitation

    Security researchers say additional flaws are being chained together and a patch will not be available until August.

    By July 15, 2026
  • Russian President Vladimir Putin speaking at a podium with a microphone.
    Image attribution tooltip
    Omer Messinger via Getty Images
    Image attribution tooltip

    US authorities warn that state-linked hackers are targeting vulnerable networking devices

    Hackers linked to Russian intelligence have exploited vulnerabilities in Cisco Smart Install devices.

    By July 13, 2026
  • A design with control v and control c keycaps
    Image attribution tooltip
    Permission granted by HERE Enterprise Browser
    Image attribution tooltip
    Sponsored by HERE Enterprise Browser

    Copy-paste might be the riskiest thing your enterprise employees do all day

    This source of data leakage takes them less than a second and happens hundreds of times a day.

    By Mazy Dar • July 13, 2026
  • A towering Citrix-branded expo sign; the tagline: "Better experience"
    Image attribution tooltip

    Citrix via Flickr

    Image attribution tooltip

    Initial access broker linked to weaponization of CitrixBleed2 flaw

    A similar pattern of exploitation was seen in prior attacks involving an open-source machine emulator. 

    By July 10, 2026
  • Jeetu Patel, president and chief product officer, Cisco, Anthony Grieco, SVP, chief security and trust officer and Cisco and Drew Hinz, product security lead, OpenAI discuss frontier AI and other security issues during a fireside chat at the Cisco Live conference in Las Vegas.
    Image attribution tooltip
    Courtesy of Cisco
    Image attribution tooltip
    Deep Dive

    Sophisticated threat campaign pushes Cisco to the very edge

    A monthslong exploitation wave against Cisco SD-WAN systems raises larger questions about trust and the insecurity of network infrastructure.

    By July 7, 2026
  • A building with large glass windows bears the Fortinet logo at the top, while a sign at ground level reads "Fortinet - 909 Kifer Road"
    Image attribution tooltip
    Courtesy of Fortinet
    Image attribution tooltip

    FortiBleed campaign traced to INC and Lynx ransomware operations

    Researchers are also investigating the role of a suspected zero-day vulnerability.

    By July 2, 2026