
What is a honeypot, and how defenders study attackers by getting hacked on purpose
Malik JohnsonDecoy systems let security teams watch real attacks unfold on machines that were built to be broken.
Daily record of disclosed breaches, exploited vulnerabilities, vendor advisories, takedowns and enforcement actions.

Decoy systems let security teams watch real attacks unfold on machines that were built to be broken.

CVE-2024-3400, a command-injection flaw in PAN-OS GlobalProtect rated 10.0 by Palo Alto Networks, was patched on April 14, 2024 — and the vendor's own advisory says exploitation began within a day of the fix shipping.

Attackers don't need to crack your password if they can wear down your patience. Here's how push bombing works and the one setting that stops it cold.

A ransomware attack at Coca-Cola's Fairlife dairy subsidiary forced production downtime in July 2026 — the latest manufacturing extortion where the machine floor, not just the office, stops.

The payment-processing provider acknowledged a ransomware incident with system disruption, reported with a June 15, 2026 extortion deadline — the latest vendor compromise rippling to merchants.

The National Association of Insurance Commissioners reported unauthorized access discovered June 11 and disclosed June 17, 2026 — a notable compromise of insurance-regulation infrastructure.