Cybersecurity
204 articles RSS
IBM and Red Hat Expand Lightwell With Commercial Offerings to Secure Open Source Software Supply Chains
IBM and Red Hat launched commercial Lightwell offerings on July 8, building on their $5 billion pledge to secure open source software supply chains.
SonicWall Patches Two Chained SMA1000 Zero-Days as CISA Sets a July 17 Deadline for Federal Agencies
CVE-2026-15409 and CVE-2026-15410 were exploited together against SMA1000 appliances before patches shipped, CISA says.
Accenture Confirms Data Breach After Hacker Claims Theft of 35GB of Source Code and Azure Keys
Accenture confirmed a security incident after a hacker known as "888" listed 35GB of alleged source code, RSA/SSH keys, and Azure access tokens for sale on a cybercrime forum.
npm v12 Ships With Install Scripts Disabled by Default After a Year of Supply-Chain Attacks
npm v12 disables install scripts, Git dependencies, and remote-URL dependencies by default, closing the execution path several npm worms exploited over the past year.
AssuranceAmerica Data Breach Exposes Driver's License Records of Nearly 7 Million People
AssuranceAmerica is notifying 6.99 million people that hackers stole driver's license numbers and insurance records after a March cyberattack on an employee account.
Coinspect Discloses 'Ill Bloom' Flaw That Has Drained at Least $5 Million From Weak-Randomness Crypto Wallets
Coinspect says a weak-randomness flaw in recovery-phrase generation, dubbed Ill Bloom, has let attackers drain at least $5 million from crypto wallets since May 27.
Sysdig Documents JadePuffer, Which It Calls the First Ransomware Attack Run End-to-End by an AI Agent Exploiting a Langflow Flaw
Sysdig says JadePuffer used an LLM agent to exploit Langflow flaw CVE-2025-3248, run 600-plus payloads, and encrypt 1,342 Nacos config items.
KDDI Data Breach Exposes Up to 14.2 Million Email Logins Across Six Japanese ISPs After Third-Party Software Zero-Day
A vulnerability in third-party email software let attackers reach up to 14.2 million KDDI ISP logins; a later update put confirmed exposure at 12.23 million addresses and 7.61 million passwords.
Aflac Japan Confirms Breach of 4.38 Million Customers and Agents After Attackers Accessed Its Policyholder Portal
Aflac Life Insurance Japan says attackers accessed its policyholder portal between June 15 and 25, exposing personal data on roughly 4.38 million customers and agents.
JetBrains Patches Critical Hub Authentication Bypass and Account Takeover Flaws Across Its IDE Ecosystem
JetBrains patched three critical Hub and YouTrack flaws enabling account takeover and authentication bypass, alongside code-execution fixes across IntelliJ, GoLand, and TeamCity.
Adobe Patches Seven Maximum-Severity ColdFusion and Campaign Classic Flaws, Each Rated CVSS 10.0 for Code Execution
Adobe's July 1 updates fix seven CVSS 10.0 flaws—six in ColdFusion, one in on-premises Campaign Classic—that can lead to arbitrary code execution.
CISA Sets a July 2 Deadline as SimpleHelp Auth-Bypass Flaw CVE-2026-48558, Rated CVSS 10, Is Exploited to Deploy Djinn Stealer
A perfect-score authentication bypass in SimpleHelp's OIDC login is being exploited in the wild to deploy TaskWeaver and Djinn Stealer, prompting CISA to give federal agencies until July 2 to patch.