Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated September 14, 2026 — all 204 published advisories are browsable here. The newest one is already under active attack: a ConnectWise ScreenConnect flaw being exploited in the wild, in the remote-support tool an IT provider uses to take control of every machine in your office (CVE-2026-84869). Behind it, a GitLab flaw rated CVSS 10, the maximum possible severity score, that lets an attacker with no login read any file off the server that stores your source code (CVE-2026-85706), and a pair of PaperCut print-management zero-days already used to break into 395 organizations, on the server that quietly sits inside the network and talks to every desktop in the building (CVE-2026-81578 and CVE-2026-82078). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
16 articles found
Featured Story
critical
Aug 11, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: Gunra Ransomware Exploits Fortinet FortiOS Auth Bypass Flaws

CISA, the FBI, and South Korea's National Police Agency issued joint advisory AA26-222A on the Gunra ransomware group, which is breaching networks through the Fortinet FortiOS and FortiProxy authentication bypass flaws CVE-2024-55591 and CVE-2025-24472. Gunra has claimed fifty-one victims across healthcare, finance, government, and manufacturing, and tampers with VDI authentication files to create a persistent MFA bypass before destroying backups and encrypting with ChaCha20.

By Danny MercerRead Full Article
critical
CVE AdvisoryVulnerabilityAug 2, 2026

CRITICAL: Coldcard Seed Flaw Linked to $70 Million Bitcoin Theft

A firmware integration error shipped in March 2021 routed Coldcard seed generation to a deterministic software PRNG instead of the STM32 hardware RNG, cutting effective entropy to as low as 40 bits. An attacker drained 1,196 Bitcoin addresses of 1,082.65 BTC worth roughly $70.2 million in 41 minutes on July 30, 2026, without ever touching a device. Coinkite shipped emergency firmware on July 31, but updating does not repair a seed that was already generated.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.