LIVE · cybersecurity feed
Live wire
vendor

Ssw

5 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical1
High2
Medium2
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-287929.6criticaltinacms\/cliTina is a headless content management system.177d ago
CVE-2026-287938.4hightinacms\/cliTina is a headless content management system.177d ago
CVE-2026-287917.4hightinacms\/cliTina is a headless content management system.177d ago
CVE-2026-241256.3mediumtinacms\/graphqlTina is a headless content management system.177d ago
CVE-2026-290666.2mediumtinacms\/cliTina is a headless content management system.177d ago

Filter the full tracker by Ssw

Our coverage of Ssw

security

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

security

Security vets rally around $4 paper password books for sale in Australia

Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026

phishing

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek.

ciscocritical

Cisco Patches Nine Flaws in Crosswork and Secure Workload Software

Cisco has released security updates addressing nine vulnerabilities affecting its Crosswork platforms and Secure Workload Software. Five of these flaws have received a critical CVSS score of 10.0. The vulnerabilities impact Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, irrespective of device configuration.

security

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise. One log that really bears looking at is the log of successful and failed logins. the call for that is:

vulnerability

N-able Bug Exposes Password Vault Master Keys

The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?

vulnerabilitycritical

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek.

security

Password spraying attacks surge 155x as hackers exploit MFA gaps

Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]

security

Passwords stored in public Google Doc then showed up in search results

Developer spotted hostname and credential string lurking in autocomplete

cloud

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model

Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the user. Users who work across multiple devices can install Enpass on Windows, macOS, Linux, Android, and iOS. Browser extensions are available for Chrome

css attackshigh

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New research reveals that sophisticated CSS-based attacks can bypass webmail security measures, enabling attackers to steal sensitive information like passwords and session tokens. These techniques exploit vulnerabilities in popular email services including Outlook, Gmail, and Yahoo Mail, potentially leading to account takeovers and data breaches. The findings highlight the need for stricter sanitization and isolation of email content.

breach

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]