Cyber News
Dashboard / Cyber News

CE
CERT Polska-2026-04-29
Vulnerabilities in Ollama software
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-42248 and CVE-2026-42249) found in Ollama software.

CE
CERT Polska-2026-04-28
Vulnerabilities in mpGabinet software
CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-40550 to CVE-2026-40552) found in mpGabinet software.

CE
CERT Polska-2026-04-20
Vulnerability in Fudo Enterprise software
Incorrect Authorization vulnerability (CVE-2025-13480) has been found in Fudo Enterprise software.

CE
CERT Polska-2026-04-14
Vulnerability in MCPHub software
Authorization bypass vulnerability (CVE-2025-13822) has been found in MCPHub project.

CE
CERT Polska-2026-04-07
Vulnerability in Bludit software
CERT Polska has received a report about a Stored Cross-site Scripting vulnerability found in Bludit software.

Mi
Mike McGuire-8 days ago
How Developers Prevent Production Risk at the Source
Fixing security vulnerabilities in code takes seconds, while patching in production creates high operational costs and risk. Discover how empowering developers as your first line of defense eliminates exposure across every phase of your software pipeline.

Se
Sean Johnstone-15 days ago
Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps
A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.

Av
Avital KatzDemocratizing FinOps with Wiz: Driving Cost Attribution with the Wiz Service Catalog
16 days ago

Wi
Wiz Threat ResearchThe State of Cloud Risk 2026: Most Security Findings Aren’t Real Attacker Opportunities
16 days ago

Ta
Tadashi Yamanaka日本のビジネスパーソンを対象としたWiz調査で 「AI導入加速」はクラウド移行を上回ることが明らかに
17 days ago

Be
Benjamin Read-22 days ago
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.

Ga
Gal Nagli-25 days ago
Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Through a Flaw in a GitHub Copilot–Assisted PR
Wiz Red Agent independently discovered and exploited a GitHub Actions injection missed by GitHub’s Advanced Security, validated access to sensitive data in Snowflake’s internal Jira, and assessed the blast radius—all without human intervention, five days after the flaw became live.

Ed
Eden Abergil-29 days ago
How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign
A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.

Ni
Nic Hall-2026-08-06
Wiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025
Automating DISA STIG Compliance for Amazon Linux 2023 and Windows Server 2025, giving defense and federal teams immediate and continuous hardening validation.

Sc
Scott Piper-2026-07-31
S3 Clones in the Neoclouds
S3 compatible services carry many of the same concerns as the original S3 service. This article highlights which assumptions break and what risks remain.

Sh
Shaked Rotlevi-2026-07-29
The Wiz Red Agent is Now Generally Available
Continuously uncover complex, exploitable risks to stay ahead in the AI Threat Era with the Red Agent



















