Hunt.io rebuilt Operation CameraSwarm from an exposed operator directory after more than 14,500 Dahua devices were compromised.
Cycode found unauthenticated command injection paths in the AIT-GUI console NASA uses to operate instruments and spacecraft.
A five-agency advisory flags an active AI-assisted campaign against internet-exposed Siemens S7 controllers across critical US sectors.
OpenAI halts frontier reinforcement learning for two weeks while it strengthens sandboxes, monitoring, and alignment defenses.
Zimperium details ToxicPanda 2.0's expanded on-device fraud while IBM flags a fresh GoldDigger campaign in South Africa and the UK.
Citrix fixed a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway that attackers are expected to exploit quickly.
Socket found 40 malicious Firefox extensions posing as Web3 products to drain recovery phrases and private keys.
Patchstack warns that a CVSS 9.0 flaw in Elementor Pro lets unauthenticated attackers upload PHP files and take over sites.
Wiz's Red Agent found a GitHub Actions injection in a Snowflake repository that exposed Jira credentials via a specially crafted…
OpenSourceMalware is tracking StubMaker, a campaign of 16 typosquatted RubyGems packages that drops a Windows infostealer on developers.
A critical arbitrary file upload bug in Forminator Forms, running on more than 600,000 WordPress sites, lets unauthenticated attackers execute PHP.
Fortinet's FortiGuard Labs uncovered Evooo1Bot, a Mirai-derived Linux botnet that turns hacked edge devices into SOCKS5 proxies.
A seller posting employee directories claims they came from Azure tenants of nine companies, and Hudson Rock says the samples…
SafePal says an authorization flaw in its order tracking plugin exposed the personal details of about 39,798 customers, but no…
CISA added an actively exploited Ray AI framework flaw to its KEV catalog, citing evidence of active exploitation in the wild.
GitLab shipped emergency patches for a critical GraphQL code injection flaw that lets unauthenticated attackers modify or delete public projects.
Check Point links nearly 2,000 hacked WordPress sites to fake-captcha malware delivery.
New Windows implant TWINLOOT abuses SharePoint and Teams to steal credentials and move laterally.
US prosecutors charge 17 Iran-linked hackers over a decade of university and corporate data theft.
Microsoft tracks 30-plus rotating domains tied to the MacSync stealer through behavioral pivots.
Scanners are hammering MLflow and FUXA servers as attackers chase cloud credentials and code execution.
Updated FBI, CISA, and HHS guidance puts Medusa ransomware victims past 500 organizations.
Varonis shows how one click on a crafted link can drain data from connected apps in Microsoft Copilot Personal.
CISA adds four actively exploited flaws covering macOS, SharePoint, vCenter, and Microsoft IKE to its urgent patch catalog.