
Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
CVE-2026-20230 is an unauthenticated SSRF in Cisco Unified CM now actively exploited after a public PoC exposed a file-write path to root. Learn the patch, workaround, and cyber-insurance controls.

LastPass Confirms Data Breach in Klue Supply Chain Attack
A legacy credential at market intelligence vendor Klue gave attackers OAuth tokens that unlocked LastPass's Salesforce environment and exposed customer records. Here is what happened and how to prevent it.

Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
Three typosquatting npm packages impersonating PostCSS utilities were caught delivering a Windows RAT with Chrome credential theft. Learn what happened and which controls stop it.

Charter, a Phone Call, and the ShinyHunters Extortion: The Vishing Playbook
No malware, no zero-day — just a phone call and missing phishing-resistant MFA. How ShinyHunters walked into a telecom giant.