Latest News

Vulnerabilities

Apache ActiveMQ CVE-2026-34197 Now Actively Exploited Days After Disclosure

A critical Apache ActiveMQ Classic flaw tracked as CVE-2026-34197, dormant in the codebase for 13 years, is being actively exploited just weeks after patched versions were released. CISA has added it to the Known Exploited Vulnerabilities catalog with a federal patch deadline of April 30.

Analysis

Why MSPs Must Rethink Security and Recovery Together — Webinar, May 14

BleepingComputer and Kaseya are hosting a live webinar on May 14, 2026, examining how AI-powered phishing, ransomware, and business email compromise are outpacing MSP defenses and why backup and recovery must be part of every security strategy.

Vulnerabilities

Microsoft Edge Update Bug Disables Right-Click Paste in Teams Desktop Client

A code regression introduced by a recent Microsoft Edge update has left Teams desktop users unable to paste content via right-click context menus. Microsoft is rolling out a staged fix while recommending keyboard shortcuts as a workaround.

Vulnerabilities

Critical RCE Vulnerability in protobuf.js Allows JavaScript Code Injection

A critical remote code execution flaw tracked as GHSA-xq3m-2v4x-88gg has been discovered in protobuf.js, a JavaScript library pulling nearly 50 million weekly npm downloads. Proof-of-concept exploit code is now public, though no active in-the-wild attacks have been observed.

Threats

Tycoon 2FA Dethroned as PhaaS Leader Following Domain Seizures and Ecosystem Shift

Cybersecurity firm Barracuda Networks reports that Tycoon 2FA has lost its dominance among phishing-as-a-service platforms after law enforcement seized 330 of its domains, with threat actors migrating to rivals like Mamba 2FA and EvilProxy while total attacks surged past 23 million.

← Prev 1 910111213 33 Next →