PaperCut shipped two emergency patches in a single day after WatchTowr found bypasses in the first fix. Two zero-days, roughly 1,000 exposed instances, and no clear attacker yet.
A 9.3 CVSS authentication bypass in NetScaler ADC and Gateway lands right when platform teams are budgeting Q4. The patch is the easy part. The vendor question is harder. ===END EXCERPT ORPHAN, ignore above and use this=== ===EXCERPT=== A 9.3 CVSS authentication bypass in NetScaler ADC and Gateway forces platform teams into an emergency patch cycle and a harder vendor conversation.
A broken Yahoo Finance page is a reminder that the "durable cybersecurity growth" narrative gets sold to boards before it gets stress-tested by the platform teams paying for it.
SafePal's order-tracking plug-in leaked names and addresses of nearly 40,000 hardware wallet customers. The keys are safe. The threat model just got worse.
A campaign called City-Forum pulled records from Salesforce and ServiceNow portals for 17 months before anyone noticed. That number should terrify every CISO.
A critical vCenter flaw went from disclosure to global APT exploitation in five days, and reverse_ssh persistence means patching alone won't evict the attacker.
AKS clusters get probed 18 minutes after creation, EKS at 28. That kills the "weekly scan" mindset and forces eBPF into the runtime critical path.