Small water utilities across the United States are getting a new line of defense. DEF CON Franklin and the National Rural Water Association have launched the Water Watch Center, a program that pairs rural water systems with managed detection and response providers following a wave of state-sponsored attacks on the…
NatJack attacks break the NAT trust model, letting same-network attackers hijack TCP sessions and poison DNS.
Zapscape, tracked as CVE-2026-64561, lets a nested KVM guest with kernel privileges escape to the host.
Tencent researchers escaped a container and reached host root through an 18-year-old SCTP use-after-free.
Swiss federal IT office BIT resets roughly 200 accounts after a Microsoft SharePoint credential theft.
A New Mexico judge brands Meta a public nuisance and orders $567M paid for child harm on its platforms.
Malware can borrow Windows Hello for Business keys to open a 90-day persistence channel into Entra ID.
A voicemail-themed AitM phishing wave is taking over Microsoft 365 accounts to harvest payroll and finance email.
CISA flags actively exploited TeamCity flaw CVE-2026-63077, giving federal agencies until August 8 to patch.
A public exploit now exists for the Cisco IMC flaw that lets low-privilege users run commands as root.
VulnCheck found a phone-home implant in Zbtlink router firmware while the vendor called it a maintenance feature.
Huntress found attackers using Oracle's own Java engine to compile malware directly inside a database.
Maksim Silnikau, the Belarusian behind the Ransom Cartel ransomware service, received a 16-year prison sentence.
Meta confirmed one of its AI models breached a company during testing, the third AI lab escape disclosed in two…
Connor Riley Moucka admitted his role in the 2024 Snowflake raids that exposed records tied to more than 100 million people.
Forescout's Vedere Labs built an attack chain from 15 flaws ending at the admin's cloud controller password.
Iran-linked actors are the leading suspects in a campaign that has hit at least 12 states since late July.
The charity CRM provider told customers to assume all stored data, including attachments, was downloaded.
Unit 42 details three ways malware can abuse Chrome's synced passkey flows to hijack accounts.
Langflow, N-able N-central, and Apache Tomcat flaws join the KEV catalog under active exploitation.
A 13-year-old memory corruption flaw ships with a public exploit covering roughly 800 kernel builds.
UK evaluators caught frontier models inventing personas and socially engineering a real open-source maintainer.
The Mini Shai-Hulud worm stole publisher credentials, republished tainted packages, and burrowed into AI coding tools.
The Police National Legal Database says contact details for officers and government staff surfaced on the dark web after an…
Sign in to your account