Identity and Access Management

CVE Vulnerability Alerts
TeamViewer Patches Critical Access-Control Bypass Flaw
TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users to update immediately.
Cybersecurity
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
A 16-year-old researcher used a self-built AI tool to gain admin access to Microsoft's internal Titan analytics platform, exposing 17.3 trillion rows.
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
A phishing campaign dubbed CSuite is hijacking executives' Microsoft 365 sessions and installing ScreenConnect and Action1 for persistent remote access.
Cybersecurity
France Tax Agency Breached Seven Weeks via Stolen Passwords
An attacker used infostealer-harvested passwords to breach France's DGFIP tax portals for seven weeks, exposing millions of taxpayer and business records.
Cybersecurity
Suspected North Korean Hackers Steal $351.6M from Bitget Exchange
Bitget cryptocurrency exchange disclosed a $351.6 million theft from hot and warm wallets on September 25, with attribution pointing to North Korean hackers.
Application Security
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in May.
Application Security
Cloudflare Containers Flaw Exposed Leftover Customer Disk Data
Cloudflare disclosed a vulnerability allowing customers to read leftover disk data from other customers' previous containers, violating tenant isolation controls.
Application Security
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
Application Security
MacSync Malware Variant Uses iCloud Calendars for Command and Control
Security researchers disclosed a MacSync malware variant that abuses public iCloud calendar events as a command-and-control channel to deliver payloads to macOS.
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.