A verified HBO Max Reddit account pushed 108 malicious ads in 48 hours, part of a broader operation spreading infostealers.
Researchers built a cheap interposer that silently drops DDR5 writes and breaks the integrity guarantees behind confidential VMs.
A crafted message can give an unauthenticated attacker root on Cisco's secure email gateway, and the flaw is already being…
A recently patched Chrome and Windows exploit chain is now delivering two separate espionage toolsets against NGO targets.
A newly named threat actor automated a July Gitea flaw into a framework that stole source code and pushed on…
Attackers are hammering internet-facing Vite development servers to pull AWS and Azure credentials and infrastructure state files.
A shared platform serving 23 ministries was breached through an unpatched VPN, with disclosure coming 78 days after detection.
A flaw fixed in July left previously exported HTML chats able to run hidden JavaScript that copies messages to an…
A government-linked Indian IT portal served a fake Cloudflare check that tried to get visitors to run a copied command.
A new AWS benchmark finds that AI models catch most real bugs but flag a huge share of safe code…
GOV.UK One Login is opening passkeys to more than 23 million users, letting them sign in without a password.
Canada's Telus says attackers used stolen credentials to reach customer records over more than a year.
A viewer add-on with tens of thousands of installs sent live Twitch session tokens to a commercial bot operator.
Firewall and proxy rules that allow the old addresses will need updating before early October.
A new Transportation Department rule lets carriers skip meal vouchers and hotels for cyberattack delays if they meet security rules.
Researchers blocked devices they never owned for under $4, exploiting six weaknesses in the lost and stolen phone system.
The commission withdrew a Biden-era statement that treated health and fitness apps as covered by federal breach notification rules.
The VPN provider says a misconfigured internal test server gave outsiders engineering material and build credentials.
Group-IB found the long-running banking trojan building a second app that shelters inside Android's employer workspace.
A forged request sent from inside a real government domain was enough to pull identity documents, selfies, and Bitcoin histories…
One cPanel account with mail rights could reach root on a shared server before this week's fix.
ConnectWise closed a ScreenConnect gap that let live sessions move and run files without consent.
Bitdefender says Google Play's Early Access program shelters thousands of deceptive apps.
Anthropic says blocked accounts in Houthi-held Yemen tried to use Claude for missile work.