Security Vulnerabilities & CVE Database

Browse the latest CVE vulnerability disclosures, CISA KEV alerts, and OSV advisories. Real-time security vulnerability database curated by 10alert.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

CISA Warns of Two Actively Exploited Vulnerabilities—Patch Now

CISA added two actively exploited vulnerabilities—CVE-2024-1708 (ConnectWise ScreenConnect path traversal) and CVE-2026-32202 (Windows privilege escalation)—to its Known Exploited Vulnerabilities (KEV) Catalog. These flaws are being leveraged by threat actors to gain unauthorized access and execute arbitrary code, impacting federal agencies under BOD 22-01 and private sector organizations globally, with urgent patching required to mitigate exploitation risks.

CVEs: CVE-2024-1708, CVE-2026-32202

#cisa #cve-2024-1708 #cve-2026-32202 #known-exploited-vulnerabilities #cybersecurity

Read full article →

NSA GRASSMARLIN Vulnerability Exposes Sensitive Data: CVE-2026-6807 Explained

NSA GRASSMARLIN (CVE-2026-6807) contains a critical XML parsing flaw enabling attackers to exploit improper external entity resolution, risking sensitive data exposure. The unsupported tool, end-of-life since 2017, remains widely deployed in critical infrastructure sectors like ICS and IT networks. Immediate mitigation is required due to the lack of vendor support and active exploitation potential.

CVEs: CVE-2026-6807

#nsa #grassmarlin #cve-2026-6807 #xml-vulnerability #cybersecurity

Read full article →

AI boom tests GOP’s midterm affordability pitch as price pain spreads

• NewsAPI.org

AI boom tests GOP’s midterm affordability pitch as price pain spreads

The global AI-driven chip shortage is exacerbating consumer price inflation, straining supply chains and increasing costs for electronic devices. This economic ripple effect is undermining GOP’s midterm affordability messaging for 2026 and disproportionately affecting low-income households reliant on affordable electronics. Supply chain disruptions and geopolitical tensions further compound the issue, requiring long-term strategic mitigation.

#security #news

Read full article →