A token instead of a password: the Check Point SmartConsole flaw
Check Point has fixed an authentication flaw in SmartConsole, the console that administers its security gateways. CVE-2026-16232 lets an unauthenticat…
Topic · Threats
How cyber threats are classified, and where to find a shared taxonomy.
Check Point has fixed an authentication flaw in SmartConsole, the console that administers its security gateways. CVE-2026-16232 lets an unauthenticat…
Langflow is a visual tool for building flows and agents on top of language models. The function meant to «validate» user-supplied code, validate_code(…
In a few weeks four widely installed Joomla extensions — SP Page Builder, iCagenda, PageBuilder CK and Balbooa Forms — landed in CISA's catalog o…
Oracle Payments is the payment engine inside Oracle E-Business Suite: the point where the company's finance applications talk to banks and card n…
On 15 July 2026 CISA added to the KEV catalog a 2023 CVE describing a 2021 attack. There is no malicious code: the attackers purge a building's K…
On 31 March 2026 two malicious axios releases added a booby-trapped dependency without touching a single line of source code. npm had rolled out OIDC …
Thirty-two Red Hat npm packages were published with malicious payloads — carrying valid SLSA provenance attestations. The technology built to guarante…
Microsoft rated it "Exploitation Less Likely". Five weeks later CISA put it in the KEV catalog with a three-day remediation window. A lesson…
Talking about “viruses” isn't enough. The security community uses MITRE ATT&CK, a public knowledge base cataloguing tactics (the “why” of an attack step) and techniques (the “how”), with stable identifiers. It's the vocabulary advisories and reports use to describe intrusions. In every one of our dossiers, technique IDs are copied from advisories, never inferred.
The ENISA Threat Landscape, the annual report of the EU cybersecurity agency, identifies seven prime threats: attacks on availability, ransomware, threats to data, malware, social engineering, information manipulation, and supply-chain attacks. The 2025 edition analysed 4,875 incidents between July 2024 and June 2025, with a clear trend: different groups reusing tools and techniques.
Most attacks don't use an exotic technique: they exploit unpatched systems, weak credentials, unnecessary exposure. Recognising threat families and mapping them onto a shared taxonomy is the first step to prioritising defences on what actually happens, not on what makes the biggest headlines.