Ninety active accounts produced most of Exploit.in's traffic, and the habits they built still shape today's ransomware crews.
UNSW researchers fine-tuned five language models on 57,000 drunk texts and watched their guardrails dissolve.
Prosecutors say Oxygen Forensics kept Russian shareholders off the paperwork while selling hacking tools to US agencies.
Microsoft says Storm-2570 swaps ransomware payloads but never swaps its tools, handing defenders a stable set of behaviors to hunt.
Two public reports on the DC health finance agency's website carried personal data in fields no visitor was meant to…
Nvidia's Open Agent Safety Platform pairs a sandbox runtime with a separate hardware monitor that can stop a stray AI…
Ardit Kutleshi admitted in a US court to running the Rydox cybercrime marketplace for a decade.
Asus says an intruder reached part of its eShop and may have taken customer contact details and order records.
Proofpoint linked 28 Microsoft 365 tenant intrusions to unrotated service accounts still holding default passwords.
Aikido Security found GitLab's per-user issue email doubles as a non-expiring token that can commit code as the account owner.
A steal-everything platform called Lunex disables endpoint defenses through a vulnerable AMD driver before it grabs browser and wallet data.
watchTowr says two unpatched NetScaler RCE flaws are being exploited and Citrix has published no fix.
A CSRF flaw in the Elementor website builder lets a single link create a rogue administrator account on millions of…
A new Windows botnet called x47.c uses xAI's Grok model to pick its next action and burns through victims' paid…
Kiteworks asked customers to run a precautionary nine-hour shutdown after federal intelligence warned of a possible attack.
A US soldier who stole call records from AT&T and others as the persona Kiberphant0m was sentenced to 70 months and $295,000 in restitution.
Microsoft tied a destructive Azure campaign to the agentic crew JADEPUFFER, which abused two hijacked service principals to wipe cloud resources.
A campaign offers fake desktop clients for three US payroll platforms, then installs ScreenConnect to give an attacker unattended access to HR machines.
A researcher published two chained OnePlus flaws that let an ordinary app gain root after the vendor warned of legal…
The documentation stand-in third-party[.]com has been weaponised, serving a ClickFix lure that poisons the clipboard on Windows machines.
Suspected North Korean thieves moved $351.6M out of Bitget's hot wallets through a spoofed transaction request.
Canada's cyber centre says a patched SQL injection in Roundcube Webmail is being exploited in the wild.
Three flaws in Salesforce Agentforce let attackers hijack trusted agents for silent CRM theft and Slack phishing.
A Chinese-speaking crook spent about $15,000 on open-source AI agents to raid hundreds of retailers and steal 600,000 card records.