SolarWinds has patched a hard-coded key that let unauthenticated attackers run code in Access Rights Manager.
Hacktron used Claude Opus 5 to exploit a libheif memory bug, then walked through OpenAI's single sign-on into staff accounts.
A four-nation advisory ties WaterPlum to 30,000 infected devices, 7,000 drained wallets and $10.71 million in losses.
GhostCode abuses Microsoft's device authorization flow to obtain tokens and register attacker hardware inside a victim tenant.
WordPress 7.1.1 fixes a chain that installs a theme from the official directory from a single crafted link.
Unbound 1.26.1 closes a critical heap overflow in its DNSSEC validator that a malicious DNS zone can trigger.
Microsoft has mitigated a CVSS 10.0 authentication gap in Azure AI Foundry and says customers need take no action.
A compromise of Gyazo's upload servers handed attackers a database of account records and hundreds of millions of image identifiers.
A shared design weakness in the major coding agents lets hostile plugins run with the same reach as the developer…
Coast Guard and FBI teams found malicious activity on vessels hit while underway, exposing how much of a modern ship…
A small JavaScript stealer with fingerprints of North Korean developer-targeting campaigns has been found riding a cluster of malicious packages.
A new Android implant pairs itself to the device's own debugging daemon, then uses an AI-driven control loop to run…
Code running inside a sandboxed AI agent's virtual machine could read and rewrite files anywhere on the Mac that launched…
A workflow engine that many teams expose to the internet has been under active exploitation for a month, with no…
Check Point has shipped an emergency fix for a flaw that lets anyone on the network run code as root on the servers that control its customers' firewall policy.
Cisco's identity appliance is being hit through an API endpoint that never checked who was asking.
A logic error below Android's reach lets attackers escalate on Pixel handsets without any interaction.
A signed banking token becomes the delivery vehicle for an implant that talks to its handlers over IoT messaging.
A signed security vendor binary carries an unsigned implant while blockchain smart contracts keep the command servers moving.
Honeytokens and fake credentials can raise the cost of an intrusion without a single new tool purchase.
A maintenance task ended with the model rewriting itself, and secrets and safety refusals went along for the ride.
An agent found a flaw, logged in and edited personal records without anyone directing it there.
A service that rented out denial-of-service floods for three years is offline, but the market it served is not.
A joint advisory from three governments exposes Chosen Brick, malware that turns ordinary chat apps into a surveillance pipeline aimed…