OWASP has formally recognized a new open source dependency scanner that runs directly in the developer terminal and produces concrete fix commands rather than simple vulnerability listings.
Microsoft's two hour auto update delay for VS Code extensions gives the community a window to catch malicious releases before…
A five step attack chain uses a malicious npm package to silently redirect Claude Code MCP traffic and steal OAuth…
Fewer than 20 Dashlane personal plan users had their encrypted vaults downloaded after an attacker targeted device registration API endpoints…
The denial of service bug in SolarWinds Serv-U requires no authentication and has been observed under active attack, prompting a…
Attackers used email bombing to set up a fake IT helpdesk call on Teams, then deployed cloud based malware within…
A logic bug in Instagram's password reset interface briefly revealed full email addresses and phone numbers including those of Meta…
A typosquatted Python package on PyPI impersonating a popular parser library deployed a Telegram backdoor to steal credentials and API…
A restricted security evaluation of Anthropic's next generation AI model was disrupted when unauthorized API access was resold through a…
Over 50 trojanized npm packages deliver a Rust-based stealer named IronWorm that uses stolen credentials to self-replicate across the supply…
Google's June 2026 Android security update patches 124 vulnerabilities, including one high severity Framework flaw already exploited in limited targeted attacks.
Millions of smart TVs are being turned into covert proxy nodes for AI training data collection through an SDK hidden…
OpenAI's Lockdown Mode blocks the data exfiltration step of prompt injection attacks by restricting outbound network requests and disabling several…
A new study reveals that 71% of SOCs report little to no value from AI despite massive adoption growth across…
The Miasma worm has compromised 73 Microsoft GitHub repositories across four organizations, with attackers exploiting previously compromised credentials to spread through interconnected projects.
Threat actors are actively exploiting a critical vulnerability in the Everest Forms Pro WordPress plugin to inject arbitrary PHP code and take over affected websites.
The critical Edge vulnerability exploits a path validation defect in feedback log processing, enabling code execution through compromised webpages or malicious files.
A Microsoft 365 service glitch caused a caching failure that made managed Windows devices appear unenrolled, allowing automatic driver installations despite configured enterprise policies.
Attackers are using cloned websites for Ghidra, dnSpy, and SpiderFoot to funnel security researchers through a traffic filtering system that…
A new China linked threat group called OP-512 is using three custom web shells with timestamp manipulation to compromise Microsoft…
A coordinated phishing campaign using over 300 cloned FIFA sites is targeting fans ahead of the 2026 World Cup, aiming…
Cisco warns that a high severity command injection flaw in Catalyst SD WAN Manager is under active exploitation, with no…
An autonomous AI agent found 21 previously undetected flaws in the FFmpeg media library, including a bug that had remained…
A newly patched SharePoint vulnerability lets authenticated users with basic permissions execute code remotely on servers, prompting Microsoft to push…
Sign in to your account