The Police National Legal Database says contact details for officers and government staff surfaced on the dark web after an incident found July 26.
Attackers used an authentication bypass in N-able N-central to reach managed endpoints, and the vendor's first fix did not block…
A researcher used AI to alter DNA evidence files in about 45 minutes, prompting Thermo Fisher to add digital signatures…
Three flaws in Hugging Face's Diffusers library let crafted model repositories run arbitrary code despite trust_remote_code protections.
River Financial Corporation told regulators it obtained assurances from the ransomware crew that breached it that stolen data was deleted.
The INC ransomware gang is the most active user of two exploited SonicWall SMA1000 flaws, adding victims across five countries…
OpenAI banned a coordinated network of ChatGPT accounts tied to Cambodian scam compounds that ran investment, romance and impersonation fraud.
Horizon3 raised $250 million in a Series E round that tripled its valuation to $2 billion, backing AI agents that…
A poisoned JavaScript file served by ad tech firm Adform rewrote crypto wallet addresses on customer sites.
Adobe patches a CVSS 10 Campaign Classic flaw that allows code execution with no user interaction.
Google's record Chrome patch wave fixed 1,442 bugs, including a Gemini-discovered flaw that hid for 13 years.
An academic study found dozens of vulnerabilities in open-source 4G and 5G core networks rooted in implicit trust.
Nebula Security showed a single page load can break Tor Browser through a Firefox JIT flaw.
Amazon attributes the debug and chalk npm hijacks to the North Korean group behind the axios attack.
A South Korean joint advisory warns that compromised websites silently infected visitors through AnySign4PC flaws.
The XCSSET malware returns as v40 with memory-only execution and a new Chrome-hijacking module.
A firmware randomness flaw in Coldcard wallets is linked to a 41-minute sweep that drained more than $70M in Bitcoin.
Kaspersky ties two memory-resident backdoors to government network intrusions across Central Asia.
Unit 42 details a DeepSeek-driven agent that launched attacks after a single Telegram command.
ShinyHunters claims a Brinks Home Salesforce breach exposing millions of records.
Anthropic found three incidents where its Claude models reached live production systems during capture-the-flag evaluations.
Wiz found a chain it calls CosmosEscape that let a crafted Gremlin query grab a platform-wide master key.
Researcher Hakon Maloy showed how hidden instructions in a Word file can alter Copilot output and copy themselves into new…
Okta's deal for Permiso Security merges identity threat detection with posture management as AI agents multiply.
Sign in to your account