AWS's new Continuum service automates the entire code vulnerability lifecycle from discovery through remediation using frontier AI models, shifting from traditional telemetry based approaches.
A junior attacker used Tailscale and OpenSSH as a backup channel to maintain access to a compromised automotive business after…
Three new malware loaders are being distributed through ClickFix social engineering campaigns targeting education, finance, and other sectors with fake…
The connectivity.office.com domain used by IT teams to verify Microsoft 365 access is showing TLS certificate expired errors, disrupting enterprise…
The updated DPAPISnoop tool parses Windows CREDHIST files to generate crackable hashes that reveal users' complete password change history through…
A North Korean threat group is targeting developers with phishing emails that lead to malicious VS Code projects, deploying cross…
Cisco urges immediate patching of CVE-2026-20262, a root privilege escalation zero-day in Catalyst SD-WAN Manager that attackers are actively exploiting.
The Council of Europe is verifying claims by the ShinyHunters group that it stole hundreds of thousands of sensitive documents…
The FBI warns that fraudsters are using couriers to collect cash from victims of cryptocurrency investment scams after traditional bank…
The SearchLeak chain weaponized three vulnerabilities in Microsoft 365 Copilot to exfiltrate sensitive data before server side sanitization could stop…
UNC6508 deployed InfiniteRed malware on REDCap servers at a North American medical research organization, remaining undetected for over a year while exfiltrating sensitive data.
Attackers tampered with JavaScript files for three popular WordPress plugins, creating hidden admin accounts and web shells only when site…
An unidentified third party exploited Maine's automated breach reporting system to post fake security incidents, prompting the state to temporarily…
A network of 152 Chrome extensions posing as wallpaper tools secretly collects user data and generates fake search traffic to…
BugHunter allows security researchers to run vulnerability testing and generate submission ready reports from a single terminal command using free local or cloud AI models.
An AI-driven fuzzing pipeline uncovered over $500,000 in bug bounties from Google by exploiting access control failures across roughly 1,500 internal APIs.
The FBI and partners seized servers, a Telegram bot, and cryptocurrency wallets, while redirecting thousands of phishing domains to a warning page.
The former IT worker conducted a 21-month cyber campaign that deleted accounts, disrupted classes, and cost over $59,000 in damages before being caught through a USB drive turned over by…
An unauthenticated attacker can exploit a missing authentication control in Splunk Enterprise's PostgreSQL sidecar to write arbitrary files and execute…
The U.S. government ordered Anthropic to immediately disable Claude Fable 5 and Mythos 5 for all users over national security…
A China linked threat group compromised Linux PAM and OpenSSH components to maintain undetected access for nearly a decade, evading…
Attackers hijacked over 400 abandoned Arch Linux AUR packages by modifying build scripts to deploy a Rust credential stealer and…
A PhaaS platform called Outsider used Google's Gemini AI to generate phishing page code, resulting in millions of stolen credit…
Tenet Security researchers discovered a technique called Agentjacking that uses crafted Sentry error reports to trick AI coding assistants into…
Sign in to your account