Attackers rewrote git tags in Laravel-Lang PHP packages to inject a credential stealing payload that executes silently on application startup.
A detailed guide to understanding how malware sandboxes provide behavioral analysis to detect evasive threats that bypass traditional signature based…
Drupal has confirmed active attacks against a critical SQL injection vulnerability in its database abstraction API affecting PostgreSQL-based sites.
Microsoft releases emergency patches for two actively exploited Defender security flaws, including a privilege escalation bug that gives attackers full…
Attackers accessed thousands of GitHub internal repositories by compromising an employee device through a malicious Visual Studio Code extension.
Qualys researchers disclosed a nine-year-old Linux kernel vulnerability that enables local attackers to gain root access and steal sensitive credentials…
A scareware kit called CypherLoc has locked browsers in an estimated 2.8 million attacks since early 2026, using full screen…
Scanning volume against SonicWall SonicOS API jumped 46 times normal levels on May 12, matching a reconnaissance pattern seen before…
A surge in attacks includes tainted JDownloader installers, deepfake sextortion targeting schools, and insider login sales by employees.
Researchers observed that vulnerable university and tech company sites were used to serve fake Cloudflare prompts that tricked visitors into…
Attackers are actively exploiting a maximum severity privilege escalation flaw in the LiteSpeed cPanel plugin that grants arbitrary script execution as root.
Security researchers uncovered a massive automated attack that injected malicious CI/CD backdoors into thousands of GitHub repositories by abusing GitHub…
Trend Micro has confirmed at least one in the wild exploit attempt against a directory traversal vulnerability in its Apex…
Google's accidental publication of an unfixed Chromium flaw allows JavaScript to run silently in browsers even after they are closed,…
A new methodology shows how to test Windows kernel driver vulnerabilities for exploitability without requiring the specific hardware the driver was built for.
A VPN service advertised on Russian cybercrime forums as a way to hide from police has been taken offline in a multinational operation across 18 countries.
Anthropic's Claude Mythos Preview AI identified over 10,000 high-severity flaws in critical software, with 97 findings already patched upstream.
A new heap overflow vulnerability in NGINX allows unauthenticated remote attackers to crash worker processes or execute arbitrary code.
Modern crypto drainer operations have evolved into structured affiliate programs that steal assets by tricking users into approving malicious blockchain…
Italian police seized servers and fined subscribers in a major crackdown on a pirate streaming app that hijacked legitimate platform…
Flipper Devices is asking developers and engineers to help build its new portable ARM Linux computer, which is designed for…
GitHub now requires human approval with 2FA for npm package publications and gives developers granular control over package install sources.
A North Korean linked threat actor uses Hugging Face's trusted platform to host malware and exfiltrate stolen data from developer…
The compromised art-template npm package silently injected a Coruna exploit kit into web applications, targeting iOS users with a watering…
Sign in to your account