Your Forgotten SQL Server Just Landed on CISA’s Emergency List

CISA has added a seven-year-old Microsoft SQL Server vulnerability to its exploited list, turning forgotten database instances into an urgent incident-response problem.

CISA has added a seven-year-old Microsoft SQL Server vulnerability to its exploited list, turning forgotten database instances into an urgent incident-response problem.

Two VMware Workstation and Fusion flaws can let an administrator inside a virtual machine execute code on the host. Versions 25H2 and 26H1 need 26H1u1.

A breach at Aesto Health reached 9.5 million people across at least two dozen providers, exposing medical, financial and identity data stored in AWS.

On some Android phones, a person holding the locked device can answer a WhatsApp video call, open Meta AI's editor and browse the photo gallery without a PIN or biometric check.

Nutex Health has confirmed that an unauthorised party accessed its network and exfiltrated information from company servers. The healthcare operator knows that data left the environment. It does not yet know, or has not publicly disclosed, whether the stolen material…

A distributed denial-of-service attack against infrastructure operated by Digdir’s supplier Vivicta disrupted access to shared digital services used across Norway’s public sector. The incident affected ID-porten and a chain of dependent services, showing how an availability attack against one provider…

Rapid7 counted twice as many high and critical disclosures, while newly exploited vulnerabilities stayed near 40. The queue is not the risk model.

Brandenburg’s seven memorial sites remained open after ransomware disabled central IT. The real resilience story was the emergency operation behind the public doors.

A critical LoadMaster command-injection flaw is being exploited. Because the appliance controls traffic at the edge, defenders should patch quickly and investigate what the device could reach or expose.

Alleged Entra directory theft exposed organisational maps rather than passwords. Treat bulk directory reads as a high-impact identity event.