Wiz's Red Agent found a GitHub Actions injection in a Snowflake repository that exposed Jira credentials via a specially crafted issue.
OpenSourceMalware is tracking StubMaker, a campaign of 16 typosquatted RubyGems packages that drops a Windows infostealer on developers.
A critical arbitrary file upload bug in Forminator Forms, running on more than 600,000 WordPress sites, lets unauthenticated attackers execute…
Fortinet's FortiGuard Labs uncovered Evooo1Bot, a Mirai-derived Linux botnet that turns hacked edge devices into SOCKS5 proxies.
A seller posting employee directories claims they came from Azure tenants of nine companies, and Hudson Rock says the samples…
SafePal says an authorization flaw in its order tracking plugin exposed the personal details of about 39,798 customers, but no…
CISA added an actively exploited Ray AI framework flaw to its KEV catalog, citing evidence of active exploitation in the…
GitLab shipped emergency patches for a critical GraphQL code injection flaw that lets unauthenticated attackers modify or delete public projects.
Check Point links nearly 2,000 hacked WordPress sites to fake-captcha malware delivery.
New Windows implant TWINLOOT abuses SharePoint and Teams to steal credentials and move laterally.
US prosecutors charge 17 Iran-linked hackers over a decade of university and corporate data theft.
Microsoft tracks 30-plus rotating domains tied to the MacSync stealer through behavioral pivots.
Scanners are hammering MLflow and FUXA servers as attackers chase cloud credentials and code execution.
Updated FBI, CISA, and HHS guidance puts Medusa ransomware victims past 500 organizations.
Varonis shows how one click on a crafted link can drain data from connected apps in Microsoft Copilot Personal.
CISA adds four actively exploited flaws covering macOS, SharePoint, vCenter, and Microsoft IKE to its urgent patch catalog.
Fake VPN installers are delivering a new backdoor to Afghan telecoms and South Asian infrastructure, with ties to APT36.
Infoblox tracks actors buying expired domains to inherit trust and traffic for malware, scams, and C2.
SAP Commerce Cloud's CVSS 10 flaw is under attack just three days after the patch shipped.
The UK criminal records office got a reprimand after attackers kept access to its CMS for seven months.
Ukraine's police shut 94 scam call centers and seized millions in cash and equipment.
Researchers prove commercial RISC-V chips are still vulnerable to Spectre attacks.
A contractor got two years for extorting Brightly Software with stolen payroll data.
XM Cyber chains four SCCM flaws to SYSTEM using a $58 certificate.