Recent
- News briefSC-2026-0320
An F5 zero-day with a Friday deadline
CVE-2026-94127 affects BIG-IP APM configured as an OAuth authorization server, is already being exploited, and CISA has ordered federal agencies to patch by Friday.
2 minSource: BleepingComputer
- News briefSC-2026-0319
Three maximum-severity flaws in ServiceNow AI
Code injection, privilege escalation and SQL injection, all reachable without authentication and without user interaction.
2 minSource: BleepingComputer
- News briefSC-2026-0318
Thirty hours against a national login
A DDoS attack on Norway's digital identity gateway took out ten services and reached the pharmacies. ID-porten serves 4.5 million users.
SeverityHigh
3 minSource: The Record
- News briefSC-2026-0317
Ninety minutes inside the build step
Three Rust crates, one of them downloaded 53 million times in ninety days, briefly shipped a dependency that ran an infostealer at compile time.
SeverityHigh
3 minSource: BleepingComputer
- News briefSC-2026-0316
Eight hours of access, 3.7 million records
CareCloud has notified 3,756,469 people. The intruder was inside one AWS environment for about eight hours in March.
2 minSource: The Record
- News briefSC-2026-0315
Three days to patch a four-month-old fix
An unauthenticated RCE in the Windows IKE service is under attack. The patch shipped in April; federal agencies now have seventy-two hours.
2 minSource: BleepingComputer
- News briefSC-2026-0314
Three months between discovery and notice
Heights Finance found the intrusion on 7 May and told 734,828 customers in August. The data includes bank accounts and social security numbers.
2 minSource: The Record
- News briefSC-2026-0313
French tax authority breach hits 678,000 records
Income, family quotient and withholding rates were extracted through access points the ministry has since closed.
2 minSource: BleepingComputer
- News briefSC-2026-0312
RingCentral breach reaches 1.6 million accounts
Have I Been Pwned put a number on a July incident the vendor described only as sophisticated social engineering.
2 minSource: BleepingComputer
- Field reportSC-2026-0311
Zero-Trust rollouts stall at the legacy boundary
The identity layer goes in cleanly. Then someone finds the manufacturing system that only speaks a protocol from 2004.
SeverityHigh
9 min
- AnalysisSC-2026-0305
DDoS volumes moved to the application layer
Network-layer floods are handled. Request-level attacks that look like real users are not.
SeverityModerate
6 min
- Research noteSC-2026-0298
Push fatigue is a process failure, not a user failure
Blaming the employee who approved the tenth prompt misses where the design went wrong.
SeverityHigh
5 min
- Field reportSC-2026-0291
Backups restore slower than anyone tested
Recovery time objectives are set on paper and validated on a single file.
SeverityCritical
7 min