Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated September 11, 2026 — all 201 published advisories are browsable here. The newest one is on the appliance that is supposed to be doing the protecting: a Cisco firewall management flaw under active attack and added to CISA's known-exploited list, on the console that controls the firewalls guarding the whole network (CVE-2026-20079). Behind it, a Chrome zero-day exploited in the wild, where simply visiting a booby-trapped site is enough to get code running on the machine (CVE-2026-87491), and a FreeIPA flaw that hands full administrator rights to anyone who connects without a password, on the directory server that decides who gets into everything else (CVE-2026-76578). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
16 articles found
Featured Story
critical
Aug 11, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: Gunra Ransomware Exploits Fortinet FortiOS Auth Bypass Flaws

CISA, the FBI, and South Korea's National Police Agency issued joint advisory AA26-222A on the Gunra ransomware group, which is breaching networks through the Fortinet FortiOS and FortiProxy authentication bypass flaws CVE-2024-55591 and CVE-2025-24472. Gunra has claimed fifty-one victims across healthcare, finance, government, and manufacturing, and tampers with VDI authentication files to create a persistent MFA bypass before destroying backups and encrypting with ChaCha20.

By Danny MercerRead Full Article
critical
CVE AdvisoryVulnerabilityAug 2, 2026

CRITICAL: Coldcard Seed Flaw Linked to $70 Million Bitcoin Theft

A firmware integration error shipped in March 2021 routed Coldcard seed generation to a deterministic software PRNG instead of the STM32 hardware RNG, cutting effective entropy to as low as 40 bits. An attacker drained 1,196 Bitcoin addresses of 1,082.65 BTC worth roughly $70.2 million in 41 minutes on July 30, 2026, without ever touching a device. Coinkite shipped emergency firmware on July 31, but updating does not repair a seed that was already generated.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.