The Bluekit phishing-as-a-service kit has adopted browser-in-the-middle techniques, allowing attackers to relay real-time login sessions and capture valid authentication tokens from victims.
Uber has appointed Philip Martin, former Coinbase CSO and ex-U.S. Army counterintelligence officer, as its new Chief Information Security Officer…
A widely used YouTube ad blocker on the Chrome Web Store has been found to contain a dormant script injection…
AI security startup Runlayer has secured $30 million in Series A funding to expand its platform that governs enterprise AI…
A joint investigation with Mandiant found that the Iranian-linked Handala group did not breach operational technology systems at California Water…
The FSB-linked Gamaredon cyber-espionage group has upgraded its malware, C2 infrastructure, and delivery tactics, enabling more covert and effective attacks…
Authorities and industry groups have dismantled a major PirloTV-linked piracy network, seizing 44 domains that funneled hundreds of millions of…
Security researchers have uncovered multiple malicious skills in the OpenClaw ClawHub marketplace that bypassed automated scans and enabled credential theft,…
Scammers are exploiting trust in Shopify’s Shop app by inserting fake purchase receipts into users’ order histories to trigger callback…
A newly discovered macOS malware campaign is weaponizing prompt injection techniques, embedding fabricated error messages to confuse AI-powered malware analysis…
An international law enforcement operation has dismantled an alleged SIM-swapping crew accused of hijacking phone numbers, stealing cryptocurrency, and laundering millions through a global network.
New forensic details reveal how threat actors leveraged a Cisco SD-WAN zero-day vulnerability to create hidden root accounts, establish persistent…
Google is rolling out new account settings that separate search activity history from personalization preferences, giving users greater control over…
A sophisticated attack chain dubbed Edgecution is abusing Microsoft Edge extensions and Chrome Native Messaging to bypass browser security boundaries,…
Threat actors have begun exploiting Cisco Unified Communications Manager vulnerability CVE-2026-20230, a critical file-write flaw that can ultimately lead to root-level compromise of vulnerable systems.
Healthcare AI company Xolis has disclosed a phishing-driven breach that exposed sensitive personal and medical data belonging to approximately 1.4 million individuals.
LastPass has confirmed that attackers used stolen OAuth tokens from a Klue supply chain breach to access Salesforce support case data containing customer contact and CRM information.
A new macOS ClickFix campaign is tricking users into running Terminal commands that silently download and mount malicious DMG files to deploy the Atomic macOS Stealer (AMOS).
CISA has warned that multiple high-severity vulnerabilities in Ubiquiti UniFi OS and Lantronix EDS5000 devices are being actively exploited, prompting…
A newly identified stealth backdoor called Mistic has been linked to the KongTuke initial access broker and is being used…
GitHub has updated actions/checkout to block common fork-based “pwn request” attack patterns in pull_request_target workflows, reducing the risk of malicious…
A new executive order establishes firm deadlines for U.S. federal agencies and contractors to transition to post-quantum cryptography, accelerating national…
Security researchers have uncovered malicious npm packages posing as PostCSS utilities that deploy a multi-stage Windows remote access trojan capable…
Tata Electronics has acknowledged a cybersecurity incident affecting parts of its IT environment after a cyber extortion group claimed responsibility…
Sign in to your account