Drupal SQL injection flaw CVE-2026-9082 added to CISA KEV as active attacks target sites.
Steve Zurier
Cisco patches critical 10.0 API flaw in Secure Workload platform.
A GitHub leak exposed CISA credentials, sparking concerns over secrets management and leadership.
Mini Shai-Hulud campaign hits 323 npm packages, GitHub Actions and VS Code tools.
Experts raise concerns because NGINX runs in front of one-third of al website worldwide.
Cybersecurity leaders warn weakened CISA could hurt AI-era defense and threat response.
Maximum-severity bug an authentication bypass flaw that’s considered the highest value target in an attacker’s playbook.
ShinyHunters hit Canvas twice, exposing student data via XSS and identity compromise.
Teams warn the latest Shai-Hulud wave weaponizes trusted OIDC tokens to bypass package integrity checks.
SailPoint says GitHub repo breach exposed no customer data or production systems.