
TeamViewer Patches Critical Access-Control Bypass Flaw
TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users

TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users

A 16-year-old researcher used a self-built AI tool to gain admin access to Microsoft’s internal Titan analytics platform, exposing 17.3

A phishing campaign dubbed CSuite is hijacking executives’ Microsoft 365 sessions and installing ScreenConnect and Action1 for persistent remote access.

An attacker used infostealer-harvested passwords to breach France’s DGFIP tax portals for seven weeks, exposing millions of taxpayer and business

Bitget cryptocurrency exchange disclosed a $351.6 million theft from hot and warm wallets on September 25, with attribution pointing to

Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in

Cloudflare disclosed a vulnerability allowing customers to read leftover disk data from other customers’ previous containers, violating tenant isolation controls.

CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following

Security researchers disclosed a MacSync malware variant that abuses public iCloud calendar events as a command-and-control channel to deliver payloads

Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.