Explore Topics

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

The Hacker News Article posted: 2h 19m ago 5 views

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assig…

WHY IT MATTERS Raises security risk for users and organizations.

Video Call Exploit Chains Two Flaws in Unisoc Modems

Dark Reading Article posted: 1h 45m ago 3 views
Story Summary

Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.

Why it matters: Raises security risk for users and organizations.

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

The Hacker News Article posted: 4h 38m ago 5 views
Story Summary

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workf…

Why it matters: Raises security risk for users and organizations.

Pokémon Center data breach exposes customer info, cancels some orders

BleepingComputer Article posted: 4h 10m ago 5 views
Story Summary

Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]

Why it matters: A breach can expose users and erode trust fast.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA Article posted: 11h 22m ago 1 view
Story Summary

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational D…

Why it matters: Raises security risk for users and organizations.

Hacker claims 3.6 million Azure account records stolen from major companies

BleepingComputer Article posted: 3h 47m ago 5 views
Story Summary

A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]

Why it matters: A breach can expose users and erode trust fast.