US Charges Say Iran’s Academic Espionage Contractors Also Sold the Data They Stole.

US prosecutors allege Mabna Institute hackers served Iranian state clients while selling stolen research and university access through commercial sites.

US prosecutors allege Mabna Institute hackers served Iranian state clients while selling stolen research and university access through commercial sites.

Cisco says attackers are exploiting a denial-of-service flaw in ASA and Secure Firewall Threat Defense. The lesson is not only to patch the VPN edge, but to design for the moment the security device itself becomes unavailable.

JetBrains closed the Cadence investigation after finding attackers could have reached current storage containing source code and credentials. The investigation is over. The risk is not.

A joint US advisory warns that attackers are using AI-assisted snap7 scripts against exposed Siemens S7 PLCs. The decisive weakness is still reachability.

Cisco fixed nine vulnerability classes across Crosswork and Secure Workload, including five with maximum CVSS scores. There are no workarounds, and several components must be upgraded together.

A password-reset email is meant to be the point where an identity system proves that the person changing a credential controls the account. A critical Keycloak flaw allowed an unauthenticated attacker to bypass that step and set a new password…

Sakura Internet's investigation expanded from 583 rented-server accounts to a separate sales system holding 1.36 million customer accounts. Access was possible, but data exfiltration was not confirmed.

ExfilSquad’s leaked data points to exposed Dataverse records, not a confirmed Dynamics exploit. Anonymous low-code permissions can be the entire breach path.

Apple has moved fixes from next-generation betas into current systems. AI is shrinking the time enterprises have to test, approve and deploy patches.

A compromised website is usually treated as the end of an incident: clean the files, reset credentials, restore the page and move on. The StopAndProtect operation shows why that model is incomplete. Almost 2,000 hijacked WordPress domains were not merely…