Browsing Category
Business
104 posts
Security Point Break covers the business of cybersecurity, from funding, acquisitions and startups to vendor strategy, market shifts and executive moves. Our reporting follows the companies, technologies and competitive forces shaping the security industry, with context for CISOs, investors, security professionals and industry leaders.
Adobe Patches 11 ColdFusion, Campaign Classic Flaws: Four Hit Max Severity
Adobe has patched 11 vulnerabilities in ColdFusion and Campaign Classic, including six critical flaws in ColdFusion that allow remote code execution. No active exploitation is reported. Users should update affected versions promptly.
Phishing Kits Abuse Microsoft Login Codes to Steal Cloud Access
LevelBlue says phishing kits are industrializing OAuth device-code attacks, giving attackers Microsoft 365 tokens without stealing a password first.
Microsoft’s Record Patch Tuesday Upstaged Within Hours by New Defender Zero-Day
Microsoft's June Patch Tuesday addressed about 200 vulnerabilities, but the emergence of a new exploit, RoguePlanet, highlights ongoing security concerns with Microsoft Defender.
Acer 5G Hotspot Has Three Critical Bugs: Patches Pending
Acer says firmware updates are coming and offers workaround fixes for three critical bugs.
Cisco Confirms Third SD-WAN Manager Zero-Day of 2026
Cisco warns of a high-severity flaw in its SD-WAN Manager, enabling attackers with netadmin access to gain root control.
CISA Pushes Oracle WebLogic Bug from Patch Backlog to Active-Exploit Priority
The agency added CVE-2024-21182 to its known exploited vulnerability catalog, giving federal agencies until June 4 to address a WebLogic Server flaw Oracle patched in July 2024.
DJI Audit Finds No Backdoors as FCC Fight Moves From Policy to Proof
DJI's independent security assessment found no significant risks in its drones, strengthening its position against U.S. regulations, despite ongoing security concerns and market uncertainties.
‘Malware-Slop’ npm Package Targets Claude AI User Files
OX Security said a malicious npm package tried to steal files from Claude user workspaces and upload them to GitHub.
Attackers Turned Trusted Developer Updates Into a Credential Trap
A supply-chain campaign hit trusted developer tools and package registries, exposing how quickly poisoned updates can steal cloud, code and CI/CD credentials.
Microsoft Quietly Patches 8 Critical Cloud Vulnerabilities
A fresh batch of Microsoft cloud security advisories included multiple critical flaws with eye-catching severity scores, but the bigger issue may be visibility rather than immediate panic.