News

KPMG Just Admitted the “Wall” Inside Its Own Firm Doesn’t Exist
KPMG admits Optus client data crossed into a Telstra audit bid. Full timeline, whistleblower retaliation, and the regulatory gaps that let it happen

Klue Salesforce Breach Explained: Icarus OAuth Attack
Inside the Klue Salesforce breach: how Icarus stole OAuth tokens, the API attack chain, IOCs, victim list, and how to detect and respond

Two 9.2s in stock NGINX: inside the HTTP/3 QPACK use-after-free and the gRPC heap overflow F5 just patched
F5 patched two critical NGINX flaws (CVSS 9.2): a QPACK use-after-free in HTTP/3 and a gRPC heap overflow. Full technical breakdown and PoCs

FortiBleed: How a Russian-Speaking Threat Group Quietly Compromised 75,000 Fortinet Firewalls Worldwide
FortiBleed exposed verified credentials for 75,000 Fortinet firewalls across 194 countries. Here's the full technical breakdown of how it was all done

How 144 Mastra npm Packages Got Poisoned in Under an Hour And Nobody Noticed Until It Was Too Late
144 Mastra npm packages were compromised on June 17, 2026 via easy-day-js, a typosquatted dependency that drops a cross-platform infostealer

How a Single Rogue BGP Announcement Took Telegram Offline Across Three Continents
A single unauthorized BGP route from Reliance AS18101 redirected Telegram's global traffic into a blackhole taking users offline in India and more

PSN’s One-Letter Username Glitch: What Actually Happened Under the Hood
A PSN glitch let users claim single-letter usernames blocked since 2006. Here's the validation failure behind it and what Sony will likely do next

The VPN Authentication Bypass That Let Ransomware Actors Walk Right In: A Deep Dive into CVE-2026-50751
CVE-2026-50751 is a CVSS 9.3 auth bypass in Check Point VPN exploited since May 7, 2026. Full technical breakdown, IOCs, patches and more

CVE-2026-53435: Inside the Jenkins Deserialization Chain That’s Being Exploited Right Now
CVE-2026-53435 is a high-severity Jenkins deserialization flaw (CVSS 8.8) under active exploitation. Full technical breakdown: gadget chain, PoC

HDFC AMC Got Breached. Here’s What Actually Happened And What Morpheus’s 680 GB Haul Means for Your Data
HDFC AMC's VMware infrastructure was breached by ransomware group Morpheus, exposing 680 GB of investor PAN, bank, and SIM data. Details





