tagEnterprise

  • Cyberattack forces UT San Antonio to delay start of fall semester
    Cyberattack forces UT San Antonio to delay start of fall semester

    The University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now start on Monday, August 24. UT San Antonio is one of the largest universities in Texas, serving more than 42,000 students. According to a statement issued by Andrea Marks, Senior Executive Vice President of Enterprise

    August 19, 2026
  • Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
    Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

    A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault

    August 19, 2026
  • Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
    Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

    GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11. “These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded

    August 18, 2026
  • Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
    Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

    GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on

    August 17, 2026
  • How MCP Servers Can Expose Enterprise Secrets
    How MCP Servers Can Expose Enterprise Secrets

    MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. The Model Context Protocol (MCP) allows AI agents to reach the tools and data,

    August 17, 2026
  • Enterprise Defenses Recovered at the Edge and Collapsed Inside
    Enterprise Defenses Recovered at the Edge and Collapsed Inside

    Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest years yet. Average prevention effectiveness

    August 12, 2026
  • UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
    UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

    A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their

    August 7, 2026
  • Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
    Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

    An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies, and its internal surface answers to strangers. Vulnerability researchers at Novee, found the path. They presented it today at Black Hat USA 2026

    August 5, 2026
  • Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
    Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

    Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,

    August 5, 2026
  • Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

    August 1, 2026
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 35
Go to
Total 343