The private equity giant says attackers hit its cloud platforms in July, exposing names and Social Security numbers.
Two exploited TrueConf Server flaws land on CISA's KEV list as Head Mare is caught delivering a poisoned installer.
Trend Micro finds 14 trojanized packages that drop the RedC2 4.0 implant the moment they are imported.
Kaspersky finds a downloader pushed through built-in firmware updaters of Android dashboards, tied to the MoYu Group.
Bitdefender ties the SilkParasite cluster to China and finds AI-assisted code in a five-RAT espionage arsenal.
Check Point weaponizes Microsoft's signed BTR.sys driver to run kernel-level operations with no flaw exploited.
A USENIX study shows expired Visa cards can be revived at checkout by rewriting the expiry read over NFC.
Adversa AI shows how ciphertext hidden in a page can make xAI's Grok hand over chat details with no warning.
Manic Android malware exfiltrates data through nearby infected devices when the victim phone is offline.
Endor Labs shows a type confusion in isolated-vm lets sandboxed code take over the host process.
Poland's CERT warns attackers are exploiting a patched Zimbra command-injection flaw in the wild.
Clop's bespoke Windchill web shell decrypts keystore credentials and maps vaults for mass exfiltration.
Google tracks three suspected Russian clusters abusing OAuth and WhatsApp to hijack targeted accounts.
The Rust project yanked three poisoned crates after a compromised account shipped a build-time backdoor.
Cisco ships patches for nine Crosswork and Secure Workload bugs, five rated at maximum severity.
Microsoft says the maximum-severity Entra ID flaw is fully mitigated and needs no customer action.
Hunt.io rebuilt Operation CameraSwarm from an exposed operator directory after more than 14,500 Dahua devices were compromised.
Cycode found unauthenticated command injection paths in the AIT-GUI console NASA uses to operate instruments and spacecraft.
A five-agency advisory flags an active AI-assisted campaign against internet-exposed Siemens S7 controllers across critical US sectors.
OpenAI halts frontier reinforcement learning for two weeks while it strengthens sandboxes, monitoring, and alignment defenses.
Zimperium details ToxicPanda 2.0's expanded on-device fraud while IBM flags a fresh GoldDigger campaign in South Africa and the UK.
Citrix fixed a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway that attackers are expected to exploit quickly.
Socket found 40 malicious Firefox extensions posing as Web3 products to drain recovery phrases and private keys.
Patchstack warns that a CVSS 9.0 flaw in Elementor Pro lets unauthenticated attackers upload PHP files and take over sites.