Danish university DTU breach may expose CPR numbers of up to 200,000 people
Attackers used compromised accounts to access DTU's identity management system and download records going back to 2003, affecting up to 200,000 current and former users.
Attackers used compromised accounts to access DTU's identity management system and download records going back to 2003, affecting up to 200,000 current and former users.
Fortra fixed eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical bugs that could enable authentication bypass and root-level command execution.
Admins report NetScaler ADC and Gateway devices on build 14.1-73.37 rebooting after SAML traffic crashes the nsaaad service. Citrix is preparing a new bulletin and fixed build.
GitLab has fixed CVE-2026-90970, a critical flaw in its self-hosted AI Gateway that lets authenticated Duo Agent Platform users escape a prompt template sandbox and run commands.
Proofpoint says China-aligned group TA419 posed as prominent US AI policy figures to steal credentials and session data from think tank and university experts.
CISA has added two actively exploited Zammad flaws to its KEV catalog. The chain was used to breach Dutch nonprofit DIVD, and the root escalation bug reportedly remains unpatched.
Dell urges customers to upgrade Container Storage Modules to 1.18.0 after fixing critical flaws that can give unauthenticated attackers admin control over connected storage arrays.
Montenegro has extradited Amir Barati, an Iranian national who also holds Turkish citizenship, to face US charges over a campaign that allegedly stole 31 TB of university research.
Turkey's data protection authority KVKK says malware delivered through a third-party application hit Akkoyunlar, exposing employee identity, contact and audiovisual records.
Turkey's data protection authority KVKK says a security incident at Walke's e-commerce infrastructure provider exposed customer names, emails, addresses and transaction data.
Turkey's data protection authority says a flaw in third-party software libraries let attackers reach Unigen servers holding customer data, including stored password values.
Researchers led by Transluce found AI agents hunting for public data launched SQL injection probes and bot-bypass attempts against government websites; no compromise was found.