Federal agents pulled down tooling that a Beijing-linked contractor used to probe power plants, airports and universities worldwide.
A single phone target carried the biggest prizes at Pwn2Own Ireland, where researchers walked away with over $1.2M in total.
Attackers are chaining two AhsayCBS bugs to plant webshells and mine cryptocurrency on exposed systems, with no vendor fix yet.
A campaign called Midnight Mimosa plants persistent, uninstallable malware inside low-cost MediaTek devices across 150-plus countries.
Researchers found 8,547 internet-facing systems at European renewable sites, including turbine dashboards with a live Stop button.
A high-severity NVIDIA exporter flaw and thousands of open monitoring ports let anyone chart, and crash, the hardware running AI…
Huntress found attackers using a fake Custom GPT to funnel victims into a ClickFix malware chain.
Microsoft traced phishing emails that drop one remote tool, then install a second, redundant one.
MI5 has publicly tied a Beijing research funder to China's civilian spy agency.
A 16-year-old used a homemade AI bot to find an auth flaw that opened Microsoft's analytics backend.
MetaMask is exiting affected Ethereum validators while it investigates an intrusion inside its infrastructure.
Two of the bugs earn a perfect 10.0 score, and Dell says there is no workaround short of upgrading.
A signed-in Duo user could break out of a prompt template sandbox and run commands on self-hosted AI Gateway hosts,…
The company's 13-million-follower account was hijacked and used to boost a token tied to an old Office mascot.
Researchers say CloudSyncD has moved from the lab to live deployment, riding in on a fake Zoom installer.
Autonomous agents hunting for public data drifted into SQL injection attempts against US and Canadian government sites.
A China-tied crew skips the dedicated command server, turning a Microsoft mailbox into its control channel instead.
Microsoft's 2026 report says attackers are reaping AI's speed gains faster than defenders can respond.
Sucuri's SC backdoor hides in eight places and rebuilds itself from any one that survives cleanup.
Longlegs and Storm-2603 keep breaching unpatched SharePoint servers to plant Warlock ransomware.
A China-aligned crew posed as a White House adviser and an economist to phish US AI policy experts.
Police seized KillSec's leak site and froze 110 terabytes of stolen data, detaining a 16-year-old they call its leader.
A 9.8-rated FortiMail flaw lets unauthenticated attackers write files, and the fix is still pending.
Truffle Security found more than half a million still-valid credentials exposed in public GitHub repositories.