As part of Dark Reading's 20th anniversary special coverage, we profile the CISOs, founders, researchers, criminals, and policymakers who rewrote the enterprise risk playbook.
Why do the Riskiest SOC Alerts Go Unanswered?
Security operations teams are drowning in alerts. But the real problem isn't always alert volume; it's the blind spots. The most dangerous alerts are the ones no one is investigating.
A recent report from The Hacker News examined why certain high-risk alert categories - WAF, DLP, OT/IoT, dark web intelligence, and supply chain signals- consistently
TeamPCP, the threat actor behind the recentsupply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI as part of a fresh Mini Shai-Hulud campaign.
The affected npm packages have been modified to include an obfuscated JavaScript file ("router_init.js") that's designed to profile the execution
A vulnerability categorized as critical has been discovered in WP Travel Plugin up to 11.4.0 on WordPress. This vulnerability affects unknown code. Such manipulation leads to sql injection.
This vulnerability is traded as CVE-2026-45218. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Saad Iqbal WP EasyPay Plugin up to 4.3.0 on WordPress. It has been rated as problematic. This affects an unknown part. This manipulation causes insertion of sensitive information into sent data.
This vulnerability appears as CVE-2026-45215. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Xpro Elementor Addons Plugin up to 1.5.1 on WordPress. It has been declared as critical. Affected by this issue is some unknown functionality. The manipulation results in sql injection.
This vulnerability is reported as CVE-2026-45214. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Vmware Spring AI up to 1.0.6/1.1.5. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Chat Memory. The manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-41712. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
Attackers are exploiting cPanel flaw CVE-2026-41940 to install the Filemanager backdoor and gain unauthorized admin access. Cybercriminals are actively exploiting the critical cPanel vulnerability CVE-2026-41940 (CVSS score of 9.3) to deploy a backdoor called Filemanager on compromised servers. cPanel is a widely used web hosting control panel that lets users manage websites and servers through a […]
A vulnerability was found in Hikvision Hik-Connect APP up to 6.10.x/6.11.x and classified as critical. Affected is an unknown function. Executing a manipulation can lead to permission issues.
This vulnerability is registered as CVE-2026-32684. The attack needs to be launched locally. No exploit is available.
It is suggested to upgrade the affected component.