CISA has added four exploited flaws in Apple macOS, Microsoft SharePoint, VMware vCenter and Windows IKE service to its KEV catalog, urging rapid patching.
An updated US government advisory warns Medusa ransomware has breached over 500 critical infrastructure organizations, with sharpened tactics complicating defense.
Healthcare IT provider CareCloud’s March 2026 breach, once thought to impact 350k people, now appears to expose data on roughly 3.7M patients, HHS data shows.
Rapid7 warns AI-accelerated vulnerability discovery and exploit development are overwhelming patch cycles, pushing defenders to focus on exposure, not CVSS.
Varonis researchers detail a Copilot Personal flaw dubbed CoSnitch, where the AI is socially engineered into exposing a hidden autorun path for one-click data theft.