The JDY botnet has expanded to over 1,500 compromised SOHO and IoT devices, acting as a high performance scanner for Chinese state sponsored threat actors to map vulnerable infrastructure at scale.
A coordinated international law enforcement operation has dismantled the AudiA6 cryptocurrency laundering service, which allegedly processed over $380 million for…
The threat actor behind The Gentlemen ransomware was identified as a 36 year old Russian from Izhevsk after transitioning from…
ESET reveals OceanLotus deployed SPECTRALVIPER backdoor in supply chain attack on Vietnamese stock investment software and a separate prolonged espionage…
Group-IB researchers uncovered a turnkey PhaaS platform enabling brand impersonation and browser hijacking through social media lures across the Middle…
The BLUERABBIT backdoor uses enterprise messaging protocols like RabbitMQ to hide its command and control traffic while enabling both data…
GoFlateLoader uses oversized PE overlays to bypass security scanning, already infecting over 33,000 users globally since April 2026.
CISA's BOD 26-04 requires federal agencies to patch critical exploited vulnerabilities within three days, replacing previous patch directives with a…
ServiceNow disclosed that threat actors exploited an unpatched configuration flaw to query a subset of customer instances before a security…
npm version 12 will require explicit user approval for install scripts and Git dependencies to block automatic code execution from…
A controlled phishing test demonstrated that the OpenClaw AI agent can be manipulated into forwarding sensitive credentials like AWS keys and database passwords with a single deceptive email.
A reverse engineering investigation reveals that free apps on smart TVs and phones act as exit nodes for a web…
A leftover debug flag in Microsoft's shared Android SDK allowed any app on the same device to steal FOCI authentication…
OpenAI launches Lockdown Mode for ChatGPT to limit outbound network requests and block data exfiltration pathways from prompt injection attacks.
A newly disclosed flaw in Veeam Backup
Attackers are exploiting an unpatched path traversal vulnerability in the Langflow AI development platform that allows unauthenticated remote code execution through file writes.
Researchers demonstrate how a single click can steal full access GitHub OAuth tokens through a vulnerability in the VS Code and GitHub.dev integration.
A critical use after free bug in OpenSSL's PKCS7_verify function allows attackers to execute arbitrary code on systems processing crafted signed messages.
The new Mythos class model routes risky cybersecurity prompts to a less capable model while offering a defensive version to…
The MLTBackdoor malware uses an automotive themed web page lure and a multi-stage infection chain involving ClickFix prompts and DLL…
A race condition exploit targeting Microsoft Defender can grant SYSTEM level access on fully patched Windows 10 and 11 systems.
Attackers are using polished TikTok and Instagram Reels clips that promise free software, directing viewers to download sites hosting the…
Attackers use a fake browser popup that mimics Microsoft's OAuth login screen to steal credentials from unsuspecting users.
Researchers found that compromised assistive AI agents in Microsoft 365 can send malicious emails using a real user's permissions, evading…
Sign in to your account