TRENDING TOPICS APR 17, 2026 CISA Sounds the Alarm on Apache ActiveMQ: A 13‑Year‑Old RCE Bug Is Now Being Actively Exploited CISA has added CVE‑2026‑34197 to its KEV catalog after confirming that attackers are actively exploiting this high‑severity remote code execution flaw in Apache ActiveMQ
TRENDING TOPICS APR 15, 2026 HanGhost Loader Targets the People Who Move Money and Goods, Not Just IT A new HanGhost loader campaign is quietly going after corporate staff who sit closest to payments, logistics, and contract workflows, using a multi‑stage, largely fileless attack chain that most SOCs only
TRENDING TOPICS APR 10, 2026 UNC6783’s Okta Phishing Playbook: When Your BPO Helpdesk Becomes the Front Door Google’s Threat Intelligence Group is tracking a new data‑theft extortion crew, UNC6783, that breaks into large enterprises by first compromising their business process outsourcers (BPOs), the third‑party support and
TRENDING TOPICS APR 08, 2026 Docker’s Silent AuthZ Failure: CVE‑2026‑34040 Turns One Oversized Request into Full Host Takeover A newly disclosed high‑severity flaw in Docker Engine, tracked as CVE‑2026‑34040 (CVSS 8.8), allows attackers to bypass authorization plugins and gain full control of the