Azure Tenant Data Theft Hits Fortune 500 Firms
A threat actor is selling millions of records allegedly stolen from Azure tenants of major companies.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A threat actor is selling millions of records allegedly stolen from Azure tenants of major companies.
Swiss messaging firm Threema faced sustained DDoS attacks this week, with changing tactics challenging defenses.
SOCRadar says most orgs hit in LiteLLM attack were earlier Trivy victims, not LiteLLM.
Researchers say ‘City-Forum’ campaign targets Salesforce and ServiceNow, possibly tied to ShinyHunters.
Akira ransomware used Windows Safe Mode to disable endpoint defenses, revealing a growing evasion trend.
A high-severity macOS bug is under attack, with hackers placing Monero miners via port 5900.
A weekly summary of key cybersecurity events, from a Boeing 737 hack demo to refrigeration flaws and Rapid7 layoffs.
Scotland's prosecution service warns 300 staff their personal data may be exposed in a cyberattack on a third-party supplier.
Researchers have uncovered a new macOS infostealer that uses ClickFix social engineering and has stealthy remote browser control capabilities.
SecurityOracle's new Database Security Central tool is free until February 2027, arriving amid rising database attacks.
A growing backlog of unresolved vulnerabilities is not a security problem but an organizational failure of ownership, capacity, and decision-making.
New batch of Apple threat notifications flags mercenary spyware attacks, urging users to take them seriously.
Flock says Audit Assistance helps curb police misuse, yet details on how it detects abuse remain unclear.
Adobe Commerce bug CVE-2026-71362 was exploited within hours of disclosure; Sansec reports active attacks.
Major acquisitions by Bank of America, CrowdStrike, and Cyera signal continued consolidation in cybersecurity.
XM Cyber researchers chain four SCCM flaws into SYSTEM access for $58, with partial fixes leaving a path open.
Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.
A developer's habit of storing passwords in a shared Google Doc led to a search-indexed exposure of staging credentials.
SecurityA presidential memo lets vetted US companies run offensive cyber ops against foreign crime rings.
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.