Security Vulnerabilities & CVE Database

Browse the latest CVE vulnerability disclosures, CISA KEV alerts, and OSV advisories. Real-time security vulnerability database curated by 10alert.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File

• NewsAPI.org

[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File

An eval injection vulnerability (CVE-2026-0013) in the CHIRP Kenwood ITM Driver allows arbitrary code execution through crafted radio configuration files. This impacts CHIRP users and Kenwood radio firmware, enabling attackers to execute malicious code by tricking users into opening a specially crafted file. Immediate patching and validation of radio configuration files is recommended.

CVEs: CVE-2026-0013

#Patch #CVE-2026-0013

Read full article →

VIDEO: Trump Tells Supporters at Rally to 'Pretend' He's on the November Ballot

• NewsAPI.org

VIDEO: Trump Tells Supporters at Rally to 'Pretend' He's on the November Ballot

In a recent rally, Donald Trump encouraged supporters to 'pretend' he was on the November ballot, which could undermine election integrity by fostering misinformation about ballot access. This action affects voter perception and trust in electoral processes, potentially influencing political behavior and election outcomes. No specific software or system vulnerability is directly implicated, but the statement heightens risks of disinformation campaigns.

#security #news

Read full article →

States Claim to Invest in “Humane” New Prisons — But Prisons Were Never Humane

• NewsAPI.org

States Claim to Invest in “Humane” New Prisons — But Prisons Were Never Humane

The article highlights how the rebranding of prisons as 'humane' or 'reformed' perpetuates systemic injustices and normalizes carceral systems. This normalization affects marginalized communities, particularly Black, Indigenous, and low-income populations, by perpetuating cycles of incarceration. The issue is not a technical vulnerability but a socio-political one, requiring systemic change rather than patching.

#security #news

Read full article →