CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.
Microsoft details a million-email CEO fraud campaign and passkey-themed attacks that compromised cloud accounts and enabled ...
A practical FinTech cybersecurity guide to protecting financial data from account takeover, API abuse, ransomware, ...
GitLab has patched CVE-2026-85706, a CVSS 10 path traversal vulnerability in the repository commits API that allows unauthenticated attackers to ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab path traversal vulnerability, ...
A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA ...
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to ...
Okta's analysis of an August 2026 infostealer-log dump found unexpired AI-service session tokens, JWTs, and encrypted JWTs that attackers could replay to access accounts without repeating password and ...
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single ...
As Backbase Backend Lead Developer for Bank of Bineo, Balkishan architects secure backend services that unify identity verification, customer data, regulatory compliance, and core banking systems into ...
The authentication gap has migrated from agent runtimes into the inference server layer. SGLang's SafeUnpickler bypass ...
Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and ...