Suspected North Korean thieves moved $351.6M out of Bitget's hot wallets through a spoofed transaction request.
Canada's cyber centre says a patched SQL injection in Roundcube Webmail is being exploited in the wild.
Three flaws in Salesforce Agentforce let attackers hijack trusted agents for silent CRM theft and Slack phishing.
A Chinese-speaking crook spent about $15,000 on open-source AI agents to raid hundreds of retailers and steal 600,000 card records.
A misconfigured storage pool let one Cloudflare container read another tenant's deleted files, forcing a cleanup of every disk.
CARBONATO hijacks exposed Docker daemons, then runs an AI agent to loot credentials and fund its own model access.
Researchers found decade-old flaws in file-notification systems that let an unprivileged process infer what other users are doing.
A research agent got past controls on a government statistics portal, prompting a taskforce review and questions about how slowly…
Cisco Talos found a Windows implant that polls four commercial AI models and acts on whichever answer wins.
Aikido traced Go malware inside two Terraform providers and two Go modules, the first abuse of HashiCorp's registry as a…
BigDiskBuster fills the system drive so Defender cannot install platform or signature updates, and there is no patch.
Island has closed a $400M Series F led by Evolution Equity Partners, pushing total funding past $1B.
The publisher says a limited redirect touched select platforms after students reported landing on the LAPSUS$ leak site.
ShinyHunters says an Oracle PeopleSoft zero-day put it inside the FBI jobs portal, and it wants a retraction rather than…
Microsoft has seized the infrastructure behind a phishing kit that used AI to pick its victims, and two suspects are on bail in London.
A path traversal bug in Check Point's management plane was already being used against customers weeks before the vendor knew it existed.
A heap overflow in BIG-IP APM hands unauthenticated attackers code execution on any appliance serving as an OAuth authorization server.
A CVSS 10.0 input validation bug in on-premises VeloCloud Orchestrator is under active exploitation, and fixes cover only two of four release trains.
Volexity has linked a China-aligned group to a three-bug Chrome and Windows chain that ran before either vendor shipped a…
WordPress 7.1.2 closes a path traversal in get_page_template() that needs no account and can end in code execution on some…
A Chinese-speaking operation pulled configuration files and hashed root credentials from 996 Zyxel GS1900 switches before federal agencies got 72…
A malicious npm package pulled two million weekly downloads while running its payload from ordinary library code instead of an…
A PowerShell backdoor built from native Windows components steals business files, Wi-Fi passwords and clipboard contents while hiding as scheduled…
An anonymous commenter could plant a script that ran in an administrator's browser and, from there, uploaded a web shell…