Manic Android malware exfiltrates data through nearby infected devices when the victim phone is offline.
Endor Labs shows a type confusion in isolated-vm lets sandboxed code take over the host process.
Poland's CERT warns attackers are exploiting a patched Zimbra command-injection flaw in the wild.
Clop's bespoke Windchill web shell decrypts keystore credentials and maps vaults for mass exfiltration.
Google tracks three suspected Russian clusters abusing OAuth and WhatsApp to hijack targeted accounts.
The Rust project yanked three poisoned crates after a compromised account shipped a build-time backdoor.
Cisco ships patches for nine Crosswork and Secure Workload bugs, five rated at maximum severity.
Microsoft says the maximum-severity Entra ID flaw is fully mitigated and needs no customer action.
Hunt.io rebuilt Operation CameraSwarm from an exposed operator directory after more than 14,500 Dahua devices were compromised.
Cycode found unauthenticated command injection paths in the AIT-GUI console NASA uses to operate instruments and spacecraft.
A five-agency advisory flags an active AI-assisted campaign against internet-exposed Siemens S7 controllers across critical US sectors.
OpenAI halts frontier reinforcement learning for two weeks while it strengthens sandboxes, monitoring, and alignment defenses.
Zimperium details ToxicPanda 2.0's expanded on-device fraud while IBM flags a fresh GoldDigger campaign in South Africa and the UK.
Citrix fixed a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway that attackers are expected to exploit quickly.
Socket found 40 malicious Firefox extensions posing as Web3 products to drain recovery phrases and private keys.
Patchstack warns that a CVSS 9.0 flaw in Elementor Pro lets unauthenticated attackers upload PHP files and take over sites.
Wiz's Red Agent found a GitHub Actions injection in a Snowflake repository that exposed Jira credentials via a specially crafted issue.
OpenSourceMalware is tracking StubMaker, a campaign of 16 typosquatted RubyGems packages that drops a Windows infostealer on developers.
A critical arbitrary file upload bug in Forminator Forms, running on more than 600,000 WordPress sites, lets unauthenticated attackers execute…
Fortinet's FortiGuard Labs uncovered Evooo1Bot, a Mirai-derived Linux botnet that turns hacked edge devices into SOCKS5 proxies.
A seller posting employee directories claims they came from Azure tenants of nine companies, and Hudson Rock says the samples…
SafePal says an authorization flaw in its order tracking plugin exposed the personal details of about 39,798 customers, but no…
CISA added an actively exploited Ray AI framework flaw to its KEV catalog, citing evidence of active exploitation in the…
GitLab shipped emergency patches for a critical GraphQL code injection flaw that lets unauthenticated attackers modify or delete public projects.