Opening the Email Was Enough. OWAReaper Stayed After the Password Changed.

Laundry Bear exploited Exchange OWA to deploy a browser implant whose mailbox access could survive password changes and endpoint rebuilding.

Laundry Bear exploited Exchange OWA to deploy a browser implant whose mailbox access could survive password changes and endpoint rebuilding.

A cyberattack against Romania’s land and cadastre agency disrupted national property services. The incident shows why recovery must restore legal confidence as well as technical availability. Romania’s National Agency for Cadastre and Land Registration, ANCPI, suffered a major cyberattack on…

The usbliter8 exploit exposed an immutable Apple SecureROM flaw. A court order removed the original research, but it could not remove the vulnerability or copies already distributed.

A malicious page could use Adobe's Acrobat Chrome extension to read WhatsApp Web content across the browser's same-origin boundary. Adobe patched the chain quickly.

Cloudflare’s Precursor analyses behaviour across a browsing session before a sensitive action occurs. The technique may catch modern automation, but it also raises privacy, accessibility and failure-mode questions. Cloudflare made Precursor generally available on 13 July as an optional capability…

Two FortiSandbox command-injection flaws are in CISA's exploited catalogue, while a related authentication bypass was reported under attack one month earlier.

The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights, security, breaches and transfers.

July 2026 Patch Tuesday covers 135 approved patch records and 682 unique CVEs across Microsoft, Adobe and SAP.

SonicWall confirmed exploitation of two SMA1000 vulnerabilities. If compromise indicators are present, defenders must rebuild the appliance and reset credentials, not merely install the hotfix.

Mandiant’s M-Trends 2026 report, published 23 March 2026, puts a number on something defenders have felt for a while: the mean time to exploit (MTTE) a vulnerability is now an estimated -7 days. Exploitation is routinely happening before a patch…