Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated September 14, 2026 — all 204 published advisories are browsable here. The newest one is already under active attack: a ConnectWise ScreenConnect flaw being exploited in the wild, in the remote-support tool an IT provider uses to take control of every machine in your office (CVE-2026-84869). Behind it, a GitLab flaw rated CVSS 10, the maximum possible severity score, that lets an attacker with no login read any file off the server that stores your source code (CVE-2026-85706), and a pair of PaperCut print-management zero-days already used to break into 395 organizations, on the server that quietly sits inside the network and talks to every desktop in the building (CVE-2026-81578 and CVE-2026-82078). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
25 articles found
Featured Story
critical
Aug 11, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: Gunra Ransomware Exploits Fortinet FortiOS Auth Bypass Flaws

CISA, the FBI, and South Korea's National Police Agency issued joint advisory AA26-222A on the Gunra ransomware group, which is breaching networks through the Fortinet FortiOS and FortiProxy authentication bypass flaws CVE-2024-55591 and CVE-2025-24472. Gunra has claimed fifty-one victims across healthcare, finance, government, and manufacturing, and tampers with VDI authentication files to create a persistent MFA bypass before destroying backups and encrypting with ChaCha20.

By Danny MercerRead Full Article
critical
CVE AdvisoryVulnerabilityAug 2, 2026

CRITICAL: Coldcard Seed Flaw Linked to $70 Million Bitcoin Theft

A firmware integration error shipped in March 2021 routed Coldcard seed generation to a deterministic software PRNG instead of the STM32 hardware RNG, cutting effective entropy to as low as 40 bits. An attacker drained 1,196 Bitcoin addresses of 1,082.65 BTC worth roughly $70.2 million in 41 minutes on July 30, 2026, without ever touching a device. Coinkite shipped emergency firmware on July 31, but updating does not repair a seed that was already generated.

Read more
high
CVE AdvisoryVulnerabilityJun 8, 2026

HIGH: Miasma Worm Detonates 73 Microsoft GitHub Repos in npm Supply Chain Cascade

GitHub disabled 73 repositories across four Microsoft organizations after the Miasma worm spread through 57 npm packages, including @vapi-ai/server-sdk and ai-sdk-ollama. The TeamPCP-linked variant of Mini Shai-Hulud uses a Phantom Gyp binding.gyp injection plus AI coding assistant rule files in Claude Code, Cursor, Gemini CLI, and VS Code to harvest AWS, GCP, Azure, Vault, and GitHub Actions credentials.

Read more
high
CVE AdvisoryVulnerabilityApr 27, 2026

HIGH: Bitwarden CLI Hit by Shai-Hulud Third Coming Worm in Checkmarx Supply Chain Cascade

A poisoned build of @bitwarden/cli version 2026.4.0 lived on the npm registry for roughly ninety minutes on April 22, 2026, infecting around 334 developer machines with the third generation of the Shai-Hulud worm. The attack chained off the prior compromise of the checkmarx/ast-github-action GitHub Action, harvested cloud credentials, GitHub and npm tokens, and AI coding tool configs, then self-propagated by injecting malicious workflows into accessible repositories.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

Page 1 of 2Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.