Okta found thousands of live AI session tokens in a stealer log, letting thieves replay their way into paid tools.
Oleksii Lytvynenko, a lawyer who coded for the Conti ransomware crew, will spend four years in a US prison.
Apple's new Watch can turn nearby speech into text and summaries, and bystanders never get a say.
Manufacturers selling software and connected products in the EU must report exploited flaws within 24 hours.
Gen Digital says a China-linked crew used a Sogou input method flaw to plant the GRAYRABBIT backdoor on Windows machines.
GreyNoise says a lone operator used hundreds of AI agents to break into 395 organizations through two PaperCut flaws.
A flaw in Brevo's single sign-on handling let an attacker blast phishing mail to 347,000 Trezor customers.
Check Point has patched two certificate-handling bugs that score 9.8 and could let an unauthenticated attacker run code.
A June intrusion at the medical equipment network reached patient and insurance data.
Washington took down Xinbi Guarantee's Telegram channels and froze $52.8M in stablecoin.
Thousands of exposed AI gateways accept the demo key printed in LiteLLM's setup guide.
A fresh proof of concept says Microsoft's fix for a Defender escalation bug leaves a gap.
A new exploit kit chained two Chrome flaws and a Windows bug for four espionage crews.
A widened transcript scan turned up another incident of a model reaching a third party.
Three exploited networking flaws now carry a three-day federal patch deadline.
CrowdStrike details Slim Spider, a Brazil-based group stealing crypto custody secrets from financial clouds.
SAP patches OVERPASS, a CVSS 10 kernel bug that lets unauthenticated attackers run commands on SAP hosts.
Check Point shows a planted instruction can make ChatGPT exfiltrate Gmail data through a covert channel between accounts.
NSA, CISA and FBI accuse China-based AI labs of industrial-scale distillation of US frontier model capabilities.
A fileless rootkit dubbed PoisonedRefresh injects PHP web shells into the memory of compromised F5 BIG-IP APM appliances.
Researchers built a zero-click worm, dubbed WeWorm, that takes over WeChat accounts through incoming calls before Tencent's August fix.
Chrome 153 closes an out-of-bounds write in V8 that Google says is exploited in the wild, the browser's seventh zero-day…
September's Patch Tuesday set a record with 974 fixes, two exploited zero-days and a cluster of potentially wormable bugs.
Grindr will pay £26M to settle a British lawsuit over pre-2020 data sharing with third parties, including HIV status information.