CVE-2026-0628: WebView Policy Bypass in Android & Chrome Enables Unauthorized Script Execution
Product: Android System WebView / Google Chrome (WebView component)Vendor: GoogleCVE ID: CVE-2026-0628CVSS v3.1 Score: 8.1 (High)Severity: HighAttack…
continue reading..
Multiple RCE and Privilege-Escalation Vulnerabilities in Veeam Backup & Replication (January 2026)
On 6–7 January 2026 Veeam published fixes for four vulnerabilities in Veeam Backup & Replication (13.x builds…
continue reading..
TridentLocker Strikes Again: How a Quiet Credential Compromise Led to a 3.4GB Data Theft
Incident Name: TridentLocker Ransomware Data TheftDate of Disclosure: January 7, 2026Target Organization: Sedgwick Government SolutionsAttack Type: Ransomware…
continue reading..
One Click Is Enough: Commodity Loader Emails Quietly Opening the Door to Full System Takeovers
Executive Summary A large-scale malicious email campaign, now commonly referred to as the Commodity Loader Campaign, has…
continue reading..
Microsoft Cancels Planned Exchange Online Bulk Email Limit
Microsoft has canceled indefinitely its previously planned daily limit on the number of external recipients Exchange Online…
continue reading..
Attackers Abuse Google Cloud Services to Steal Microsoft 365 Credentials
Cybersecurity researchers have uncovered an ongoing phishing campaign where threat actors are actively misusing Google Cloud infrastructure…
continue reading..
CVE-2025-13744: Stored XSS in Search & Filter Views Enables Session Hijack and Admin Compromise
CVE-2025-13744 Vulnerability Type: Cross-Site Scripting (XSS)Category: Web Application – Stored XSSCVSS Score: 8.4Severity: HighAttack Vector: NetworkAttack Complexity:…
continue reading..
CVE-2025-47388: Qualcomm DSP Memory Corruption Exposes Android Devices to Kernel Crash and Privilege Escalation
Executive Summary What This Vulnerability Is CVE-2025-47388 is a memory corruption flaw in Qualcomm’s DSP service, a…
continue reading..
CVE-2025-15471: Critical Unauthenticated OS Command Injection in TRENDnet TEW-713RE Router
Executive summary There’s an OS command-injection flaw in the TEW-713RE web management stack. An attacker who can…
continue reading..
