A trojanized Newtonsoft.Json fork on NuGet smuggles game-rigging malware inside a fully functional serialization library to evade detection.
OpenAI and Anthropic models broke rules in cybersecurity tests and failed to admit it, with cheating rates between 7.8% and…
Have I Been Pwned confirms the massive breach of the AI music platform, including email addresses and partial credit card…
CVE-2026-6875 lets attackers bypass the ServiceNow script sandbox through a JavaScript override technique, with exploitation already in the wild.
German and US law enforcement seized 200 servers and arrested the alleged developer of the Kratos phishing platform in Indonesia.
Attackers are exploiting a critical SharePoint RCE vulnerability to steal machine keys, and patching alone won't lock them out.
A large-scale supply chain attack dubbed FakeGit uses thousands of deceptive GitHub repositories to distribute SmartLoader malware.
Publicly released exploit code for the WordPress core wp2shell vulnerability is fueling widespread mass scanning and site takeover attempts.
Attackers used CVE-2026-15409 and CVE-2026-15410 to compromise SonicWall SMA 1000 appliances via SSRF and code injection starting June 22.
Attackers are exploiting CVE-2026-6875, a critical pre-authentication RCE in the ServiceNow AI Platform, just days after disclosure.
Cosmetics giant Estee Lauder notifies customers of a data breach tied to a Clop-exploited Oracle E-Business Suite vulnerability.
Iran-nexus threat groups are using generative AI for malware development, industrial control system mapping, and multilingual phishing campaigns.
A heap buffer overflow in 7-Zip's XZ decompression lets attackers execute code when victims open crafted archive files.
Hugging Face confirmed an autonomous AI agent breached its infrastructure through a malicious dataset in the company's data processing pipeline.
F5 patched a critical Nginx heap buffer overflow that lets unauthenticated attackers crash workers or achieve remote code execution.
Russian intelligence operatives compromised IP cameras across NATO states and Ukraine to monitor military supply movements in real time.
Singapore-based quantum-safe cybersecurity startup pQCee raises $3.9M seed round co-led by SGInnovate and Lotus One Investment.
North Korean threat actors embed malware payload fragments inside SVG country flag images distributed through fake developer job interviews and coding challenges.
Kaspersky uncovers GoSerpent, a Go-based backdoor targeting government and diplomatic entities in Southeast Asia since late 2025 for long-term intelligence…
SAP releases July 2026 security updates for a critical memory corruption flaw in NetWeaver ABAP and two additional CVSS 9.1…
The OkoBot malware framework injects fake recovery seed phrase pages directly into legitimate Ledger and Trezor desktop applications on Windows…
The European Commission orders Google to give rival AI assistants the same hardware access as Gemini under the Digital Markets…
Symantec discovered Spirals, a Rust-based ransomware that encrypted an IT services company's network in less than a day.
Zoom fixed CVE-2026-53412, a critical account takeover vulnerability with a CVSS score of 9.8 affecting Windows users.
Sign in to your account