Jamf Threat Labs details a three-stage Rust stealer that harvests macOS credentials and gives operators live, hidden control of the victim's browser.
A free archive with 7.3 million Chess.com records looks like large-scale scraping, though one internal-facing detail needs explaining.
watchTowr logged hundreds of exploitation probes against an unpatched GeoServer SQLi bug within hours of its disclosure.
Huntress says an Akira affiliate rebooted a victim into Safe Mode to kill EDR, then the encryptor crashed on the…
Sansec blocked the first exploits of CVE-2026-71362, an unauthenticated account takeover in Adobe Commerce rated 9.1.
Trellix found dark web services like APEX AI and MessiahGPT that lower the skill bar for ransomware-grade attacks.
A breach at shipping partner ShipMonk exposed names, emails and addresses for over 13,000 Trezor customers.
CERT-UA ties fake recruiter lures to Sandworm subgroup UAC-0145, which hides PowerShell execution inside a poisoned WireGuard client.
Socket finds 737 VPN and proxy add-ons funneling browser sessions through a single provider.
Reco tracks a long-running campaign harvesting records from over-permissioned SaaS portals.
A July cyberattack on CEVA Logistics halted shipments and exposed customer details for Valve and others.
A new White House program would let private firms run offensive operations under federal oversight.
Israeli firm Dream documents what appears to be the first autonomous AI attack on a government.
A researcher's ShieldBreak PoC claims to bypass Microsoft's fix for the Defender RoguePlanet flaw.
Check Point ties a Windows zero-day to Lazarus attacks on defense firms using fake job offers.
Attackers are exploiting a critical SharePoint authentication bypass days after Rapid7 shipped proof-of-concept code.
Robinhood Ventures Fund II's listed debut puts retail money behind AI security, identity, and counter-drone startups.
Microsoft's August update batch closes 398 flaws led by a WinSock driver zero-day already under attack.
Adobe's August security batch includes three CVSS 10.0 bugs in ColdFusion and Campaign Classic with a Priority 1 rating.
A CloudSEK dataset maps the March LiteLLM poisoning campaign to secret exposure at thousands of organizations.
Attackers are exploiting a patched vCenter flaw to plant reverse SSH tunnels and hold onto compromised servers.
Cisco warns an unauthenticated attacker can crash ASA and FTD firewalls with a single crafted HTTP request.
Unit 42 documents Kimwolf v7, a rebuild that hides DDoS floods behind browser fingerprints and Ethereum domains.
SAP's August update fixes a CVSS 10.0 hole letting unauthenticated attackers run code in Commerce Cloud.
Sign in to your account