Vulnerabilities

AWS Patches Critical Flaw in Seven Software Development Kits
IT Security & Compliance AWS Patches Critical Flaw in Seven Software Development Kits

During authorized testing, researchers successfully captured Kubernetes service account tokens by redirecting API calls from an EKS workload to a controlled callback server. This discovery originated from a seemingly minor oversight in how Amazon Web Services (AWS) handled input validation within

How Did the Latvia CSDD Breach Expose Millions of Records?
IT Security & Compliance How Did the Latvia CSDD Breach Expose Millions of Records?

The long-term impact of the breach is expected to drive a comprehensive overhaul of how the Latvian government protects centralized citizen databases. This massive cybersecurity failure at the Road Traffic Safety Directorate (CSDD) has sent shockwaves through the Baltic region, serving as a stark

Will Your Samsung Galaxy Tablet Be Supported Until 2032?
Mobile Technology & Gadgets Will Your Samsung Galaxy Tablet Be Supported Until 2032?

Budget-oriented users purchasing the Galaxy Tab A9+ today should prepare for a relatively short support window that concludes as early as October 2026. This reality highlights a significant divide within the current tablet landscape, where affordable hardware often sacrifices longevity for

Isolated-VM Vulnerability Allows Sandbox Escape and Code Execution
IT Security & Compliance Isolated-VM Vulnerability Allows Sandbox Escape and Code Execution

The vulnerability tracked as GHSA-864f-rcv7-6rh4 demonstrates that even if a host shares only a single reference with a sandbox, an attacker can still construct a functional exploit to escape. This flaw targets the isolated-vm library, a popular Node.js extension used to create secure environments

CYFIRMA Weekly Report: Emerging Ransomware and Global Cyber Threats
IT Security & Compliance CYFIRMA Weekly Report: Emerging Ransomware and Global Cyber Threats

A critical vulnerability in the Vault Secrets Operator for Kubernetes, tracked as CVE-2026-8715, allows authenticated users to exfiltrate cluster-wide secrets to external endpoints. This alarming discovery highlights the ongoing fragility of cloud-native infrastructure as organizations continue to

Agent Tesla Campaign Uses Emojis to Hide Fileless Malware
IT Security & Compliance Agent Tesla Campaign Uses Emojis to Hide Fileless Malware

Data exfiltration in this campaign is handled via the FtpWebRequest protocol, with stolen credentials and contact lists sent to a C2 infrastructure hosted at ftp.melrz.com. This specific operational detail highlights the brazen nature of a new wave of Business Email Compromise (BEC) attacks

Loading

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later