CVE/vulnerability
Critical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands
Splunk has addressed a critical vulnerability in Splunk Enterprise that allows unauthenticated attackers to execute operating system commands through the Patroni REST API on...
cyber security
ChainDrop and PolinRider Use Blockchain C2 to Steal Cloud and CI/CD Credentials
Threat actors are increasingly using blockchain networks as resilient command-and-control infrastructure to steal cloud credentials from developer endpoints and CI/CD environments.
Recent campaigns involving...
Cyber Security News
Attackers Hijack .gh, .sl, and .as Domains to Obtain Unauthorized SSL Certificates
Attackers compromised the infrastructure of third-party country-code top-level domains (ccTLDs) for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as).
They modified authoritative DNS...
Cyber Security News
12 Best ASPM Platforms Compared (2026): Features & Pricing
Apiiro leads risk-graph depth, ArmorCode aggregation breadth, and the acquisition wave (Dazz into Wiz, Bionic into CrowdStrike, Enso into Snyk) tells you where ASPM...
Cyber Security News
12 Best SCA Tools Compared (2026): Features & Pricing
Snyk is the best developer-platform SCA, Sonatype the repository-firewall powerhouse, and Socket the malicious-package specialist the CVE-scanners aren’t.
Twelve options priced across free-floor, developer, registry,...
Cyber Security News
Discord Security Bot Double Counter Hacked, Exposing Data of Millions of Users
The Discord security bot Double Counter experienced a targeted infrastructure breach that compromised personal information linked to millions of accounts.
According to an incident...
Cyber Security News
9 Best IAST Tools Compared (2026): Features & Pricing
Contrast Security remains the dedicated IAST anchor, Black Duck’s Seeker the QA-leverage specialist, and Dynatrace/Datadog prove the category’s future is observability-delivered.
Our source sheet’s twelve...
Cyber Security News
12 Best DAST Tools Compared (2026): Features & Pricing
PortSwigger’s Burp Suite anchors practitioner testing at published prices, Invicti leads proof-based fleet automation, and Bright Security heads the developer-CI insurgents.
Twelve options across five...