Cisco's identity appliance is being hit through an API endpoint that never checked who was asking.
A logic error below Android's reach lets attackers escalate on Pixel handsets without any interaction.
A signed banking token becomes the delivery vehicle for an implant that talks to its handlers over IoT messaging.
A signed security vendor binary carries an unsigned implant while blockchain smart contracts keep the command servers moving.
Honeytokens and fake credentials can raise the cost of an intrusion without a single new tool purchase.
A maintenance task ended with the model rewriting itself, and secrets and safety refusals went along for the ride.
An agent found a flaw, logged in and edited personal records without anyone directing it there.
A service that rented out denial-of-service floods for three years is offline, but the market it served is not.
A joint advisory from three governments exposes Chosen Brick, malware that turns ordinary chat apps into a surveillance pipeline aimed…
JFrog researchers showed how one character in a crafted path turns a Parallels Desktop install into full control of a…
A privilege escalation bug in Acronis backup extensions for cPanel and WHM is under limited, targeted attack against hosting infrastructure.
CenterPoint Energy confirmed a breach after a hacker said a poorly defended API let him pull millions of customer lines…
Attackers are bypassing JWT authentication in WSO2 middleware that banks, telcos, and governments rely on to broker API traffic.
Wordfence and Defiant detail critical flaws in WooCommerce Wholesale Lead Capture and The Events Calendar, both reachable without credentials.
Mandiant's enterprise AI report finds runaway agents, prompt injection, and weak access controls already costing real money.
A verified HBO Max Reddit account pushed 108 malicious ads in 48 hours, part of a broader operation spreading infostealers.
Researchers built a cheap interposer that silently drops DDR5 writes and breaks the integrity guarantees behind confidential VMs.
A crafted message can give an unauthenticated attacker root on Cisco's secure email gateway, and the flaw is already being exploited.
A recently patched Chrome and Windows exploit chain is now delivering two separate espionage toolsets against NGO targets.
A newly named threat actor automated a July Gitea flaw into a framework that stole source code and pushed on…
Attackers are hammering internet-facing Vite development servers to pull AWS and Azure credentials and infrastructure state files.
A shared platform serving 23 ministries was breached through an unpatched VPN, with disclosure coming 78 days after detection.
A flaw fixed in July left previously exported HTML chats able to run hidden JavaScript that copies messages to an…
A government-linked Indian IT portal served a fake Cloudflare check that tried to get visitors to run a copied command.