Nissan Americas confirmed a data breach after attackers exploited CVE-2026-35273 in Oracle PeopleSoft, exposing employee data across four countries.
The latest version of this malware is harder to detect and spreads through disguised files and a Telegram based command…
Google's latest Chrome update fixes 18 vulnerabilities, including two critical WebGL use-after-free bugs that could allow sandbox escape attacks.
Microsoft discovered 119 malicious Edge extensions using steganography and selective activation to steal credentials and session cookies from 2.6 million…
The bounty targets UNC5792 and UNC4221, groups linked to Russia's FSB and military that have compromised thousands of messaging app…
NAIC confirms the ShinyHunters breach of its Oracle PeopleSoft system exposed only public financial reports and configuration files, not sensitive…
Attackers exploit a critical SimpleHelp flaw to deploy TaskWeaver loader and Djinn Stealer, which targets credentials for AI development tools,…
Researchers at Mozilla's 0DIN platform show how AI coding agents can be tricked into executing malware by following standard setup…
Attackers can already harvest encrypted credentials today, storing them for future decryption when quantum computers arrive, making a credentials first…
The Meta owned messaging service will let users reserve a unique handle and an optional key to control who can…
The campaign used fake SMS messages disguised as messaging support bots to trick Ukrainian officials and activists into revealing account credentials.
New malware strains SHARDLOADER, MINIRECON, and ZOHOMURK use legitimate cloud storage to blend malicious traffic with normal activity, targeting government…
Microsoft linked StegoAd to the DarkSpectre operation, noting overlapping techniques and shared infrastructure with the GhostPoster extension campaigns previously identified.
Microsoft discovered a malicious Chrome extension impersonating Perplexity AI that captured user searches and address bar input before redirecting to…
A widely used Chrome ad blocker with millions of users contains inactive code pathways that could allow attackers to inject malicious scripts on any website without an extension update.
Researchers detail a three flaw exploit chain where a malicious web page loaded by an AI agent can execute code on the host machine through an unauthenticated local service.
Researchers identified over 236,000 domains using the DCloud framework for cryptocurrency scams, pig butchering operations, and wallet drainers active since mid-2022.
Mozilla researchers demonstrate how AI coding agents can be tricked into opening reverse shells through clean-looking repositories, with payloads hidden entirely in DNS records.
NetSPI researchers discovered that attackers can bypass Microsoft Entra Conditional Access Policies by abusing the Nested App Authentication OAuth flow…
The EvilTokens phishing kit encrypts its landing page content with AES GCM to bypass static URL analysis, exploiting Microsoft's device…
Nation state actors exploit default credentials and internet facing PLCs to access water infrastructure, altering chemical dosing and opening floodgates…
OpenAI's GPT-5.6 Sol launches with layered cyberattack protections and government-mandated access controls after national security concerns from the Trump administration.
Dell patches two serious vulnerabilities in its Wyse Management Suite that could allow attackers to take complete control of affected…
The platform autonomously executes 33 security tools like Nmap and SQLMap inside an isolated Docker sandbox with real time AI…
Sign in to your account