A poisoned JavaScript file served by ad tech firm Adform rewrote crypto wallet addresses on customer sites.
Adobe patches a CVSS 10 Campaign Classic flaw that allows code execution with no user interaction.
Google's record Chrome patch wave fixed 1,442 bugs, including a Gemini-discovered flaw that hid for 13 years.
An academic study found dozens of vulnerabilities in open-source 4G and 5G core networks rooted in implicit trust.
Nebula Security showed a single page load can break Tor Browser through a Firefox JIT flaw.
Amazon attributes the debug and chalk npm hijacks to the North Korean group behind the axios attack.
A South Korean joint advisory warns that compromised websites silently infected visitors through AnySign4PC flaws.
The XCSSET malware returns as v40 with memory-only execution and a new Chrome-hijacking module.
A firmware randomness flaw in Coldcard wallets is linked to a 41-minute sweep that drained more than $70M in Bitcoin.
Kaspersky ties two memory-resident backdoors to government network intrusions across Central Asia.
Unit 42 details a DeepSeek-driven agent that launched attacks after a single Telegram command.
ShinyHunters claims a Brinks Home Salesforce breach exposing millions of records.
Anthropic found three incidents where its Claude models reached live production systems during capture-the-flag evaluations.
Wiz found a chain it calls CosmosEscape that let a crafted Gremlin query grab a platform-wide master key.
Researcher Hakon Maloy showed how hidden instructions in a Word file can alter Copilot output and copy themselves into new documents.
Okta's deal for Permiso Security merges identity threat detection with posture management as AI agents multiply.
North Korea-linked actors are using fake full-screen macOS updates to push ClickFix-style clipboard attacks.
CVE-2026-60004 lets a repository writer plant a git hook and run commands as the Gitea service account.
Hackers stole personal, financial and medical data from CareCloud's AWS environment in March.
Research finds tens of thousands of internet-facing BMCs disclosing IPMI password hashes without authentication.
A CVSS 9.5 Rails Active Storage flaw lets unauthenticated attackers read arbitrary server files through crafted image uploads.
Ruflo's unauthenticated MCP bridge earns a perfect CVSS 10 as researchers demonstrate AI memory poisoning.
CISA adds actively exploited Cisco FMC static credentials flaw to its known vulnerabilities catalog.
TA488 exploits OWA cross-site scripting flaw to plant browser implants that survive credential rotation.
Sign in to your account