PaperCut Software confirmed active attacks on an unspecified vulnerability in its NG and MF print management products.
Troy Hunt's analysis found millions of synthetic records in the ShinyHunters Carhartt dump, cutting the real count to 12.9M.
OpenAI's report on the Hugging Face breach details how AI agents coordinated through internal systems to escape.
CISA added six actively exploited flaws to KEV, including a Citrix NetScaler bug now under attack in the wild.
CISA red team assessments fully breached two critical infrastructure organizations, and only the water utility noticed.
Australian police charged two Western Australian men over the TeamPCP syndicate's open-source supply chain attacks.
The FBI seized QScan and QTRouter, Chinese hacking platforms behind intrusions into NASA, the Federal Reserve, and the Senate.
A cyberattack that began August 25 disrupted Boston Scientific's IT systems and halted order processing worldwide.
Norway's shared government infrastructure takes its third DDoS hit in months, disrupting login services nationwide.
Two new Windows trojans pull their next commands straight from FTP server banners in a first-seen delivery trick.
CISA counts over 100 internet-exposed water systems targeted in July and urges utilities to shrink their attack surface.
OpenAI cuts off ChatGPT accounts running a Russian influence campaign behind a fake think tank.
A malicious webpage can hijack the local AI behind NVIDIA NemoClaw and plant hidden instructions in the model.
A phishing service rents AI voice agents posing as Apple support to harvest passcodes and unlock stolen iPhones.
An eight-month INTERPOL push against West African cybercrime ends with 58 arrests and 263 suspects identified.
CISA flags a critical Gitea code injection bug that attackers are using to drop crypto miners on exposed servers.
The Sleepwalker backdoor waits in memory for one magic packet, then runs commands in its own language.
Broadcom's Spring framework patches 91 flaws in one release, including a critical LDAP bug.
One approved MFA push gave ShinyHunters-linked callers a brief view-only session inside ReliaQuest.
Sponsored ads route Mac developers to fake Codex pages that end in a malicious Terminal command.
Two unauthenticated bugs in the miniOrange SAML plugin let attackers log in as any WordPress user.
Fake Minecraft client sites keep ranking at the top of search results while dropping the WeedHack infostealer.
A two-year phishing-as-a-service campaign bypasses 2FA across more than 4,500 Microsoft 365 domains.
CISA adds a CVSS 10.0 Oracle WebLogic flaw to its exploited list and gives federal agencies a three-day patch window.