Vendor Security News
Vendor security advisories, disclosures and statements from software and hardware makers about issues in their own products.
When a vendor issues its own security advisory (acknowledging a flaw, describing its impact, announcing a fix) it is usually the most authoritative account of what happened. Coverage here ranges from routine bulletins to public statements after in-the-wild exploitation. It is the direct-from-the-source counterpart to third-party CVE and exploit reporting.
Recent Vendor items
Other topics
CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.