BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
DentaQuest data breach exposed info of 2.6 million accountsBleepingComputer · 2h agoiFood Confirms Data Breach Affecting 1.2 Million Users in BrazilHackRead · 3h agoCisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes PublicThe Hacker News · 3h agoUN food agency discloses breach affecting 600,000 Gaza householdsBleepingComputer · 4h agoEverest Forms Pro Vulnerability Allows Remote Code Execution on WordPress SitesInfosecurity Magazine · 4h agoNew IronWorm malware hits 36 packages in npm supply-chain attackBleepingComputer · 5h agoClaude Code GitHub Action Flaw Let One Malicious Issue Hijack RepositoriesThe Hacker News · 5h agoAgentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize ItThe Hacker News · 5h agoWhy eSIMs Are Replacing Traditional SIM CardsHackRead · 5h agoChinese spies are using LinkedIn to lure Westerners into sharing sensitive informationTechCrunch Security · 5h agoHackers Are After the Gaps in Your Vulnerability Program: Here's Their PlaybookBleepingComputer · 6h agoThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News · 6h agoInfosecurity Europe: AI Adoption Creates New Opportunities for Attackers to Distribute Malware, Microsoft WarnsInfosecurity Magazine · 6h agoChinese-Speaking Actor TA4922 Widens Its Global ReachInfosecurity Magazine · 6h agoHow the “Swiss Cheese” model can help you choose the right MDR providerRapid7 · 7h agoDentaQuest data breach exposed info of 2.6 million accountsBleepingComputer · 2h agoiFood Confirms Data Breach Affecting 1.2 Million Users in BrazilHackRead · 3h agoCisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes PublicThe Hacker News · 3h agoUN food agency discloses breach affecting 600,000 Gaza householdsBleepingComputer · 4h agoEverest Forms Pro Vulnerability Allows Remote Code Execution on WordPress SitesInfosecurity Magazine · 4h agoNew IronWorm malware hits 36 packages in npm supply-chain attackBleepingComputer · 5h agoClaude Code GitHub Action Flaw Let One Malicious Issue Hijack RepositoriesThe Hacker News · 5h agoAgentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize ItThe Hacker News · 5h agoWhy eSIMs Are Replacing Traditional SIM CardsHackRead · 5h agoChinese spies are using LinkedIn to lure Westerners into sharing sensitive informationTechCrunch Security · 5h agoHackers Are After the Gaps in Your Vulnerability Program: Here's Their PlaybookBleepingComputer · 6h agoThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News · 6h agoInfosecurity Europe: AI Adoption Creates New Opportunities for Attackers to Distribute Malware, Microsoft WarnsInfosecurity Magazine · 6h agoChinese-Speaking Actor TA4922 Widens Its Global ReachInfosecurity Magazine · 6h agoHow the “Swiss Cheese” model can help you choose the right MDR providerRapid7 · 7h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

VulnerabilityFortinet PSIRT·51d ago
Arbitrary directory delete on vmimages delete feature

CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. Revised on 2026-04-14 00:00:00

🔴 BreachFortinet PSIRT·51d ago
Axios npm Package Compromised

On March 31, 2026, the Axios npm package was compromised via a maintainer account takeover. Two malicious versions were published - [email protected] and [email protected] - which introduced a hidden dependency ([email protected]) able to execute a post‑install script deploying a cross‑platform Remote Access Trojan (RAT) on Windows, macOS, and Linux systems. Revised on 2026-04-14 00:00:00

VulnerabilityFortinet PSIRT·51d ago
Heap-based buffer overflow in oftpd daemon

CVSSv3 Score: 7.3 A heap-based buffer overflow vulnerability [CWE-122] in FortiAnalyzer Cloud oftpd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation Revised on 2026-04-14 00:00:00

VulnerabilityFortinet PSIRT·51d ago
Missing Authentication for critical function in CAPWAP daemon

CVSSv3 Score: 6.2 A missing authentication for critical function vulnerability [CWE-306] in FortiOS and FortiSwitchManager CAPWAP daemon may allow a local unauthenticated attacker on the same local IP subnet to write device configuration via specially crafted requests. To be successful, this attack requires the targeted FortiGate device to run a specific, non default configuration. Revised on 2026-04-14 00:00:00

VulnerabilityFortinet PSIRT·51d ago
Multiple SQL Injections

CVSSv3 Score: 7.1 An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS may allow an authenticated attacker to run arbitrary SQL queries on the database via sending crafted requests. Revised on 2026-04-14 00:00:00

VulnerabilityFortinet PSIRT·51d ago
Multiple Stored XSS

CVSSv3 Score: 4.3 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox and FortiSandbox Cloud may allow a privileged attacker to perform a stored XSS attack via crafted HTTP requests. Revised on 2026-04-14 00:00:00

🩹 PatchThe Hacker News·51d ago
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild. The vulnerability in question is CVE-2025-0520 (aka CNVD-2020-26585), which carries a CVSS score of 9.4 out of 10.0. It relates to a case of unrestricted file upload that stems from improper validation of

VulnerabilityThe Hacker News·51d ago
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added half a dozen security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is as follows - CVE-2026-21643 (CVSS score: 9.1) - An SQL injection vulnerability in Fortinet FortiClient EMS that could allow an unauthenticated attacker to