Iran-nexus threat groups are using generative AI for malware development, industrial control system mapping, and multilingual phishing campaigns.
A heap buffer overflow in 7-Zip's XZ decompression lets attackers execute code when victims open crafted archive files.
Hugging Face confirmed an autonomous AI agent breached its infrastructure through a malicious dataset in the company's data processing pipeline.
F5 patched a critical Nginx heap buffer overflow that lets unauthenticated attackers crash workers or achieve remote code execution.
Russian intelligence operatives compromised IP cameras across NATO states and Ukraine to monitor military supply movements in real time.
Singapore-based quantum-safe cybersecurity startup pQCee raises $3.9M seed round co-led by SGInnovate and Lotus One Investment.
North Korean threat actors embed malware payload fragments inside SVG country flag images distributed through fake developer job interviews and…
Kaspersky uncovers GoSerpent, a Go-based backdoor targeting government and diplomatic entities in Southeast Asia since late 2025 for long-term intelligence…
SAP releases July 2026 security updates for a critical memory corruption flaw in NetWeaver ABAP and two additional CVSS 9.1…
The OkoBot malware framework injects fake recovery seed phrase pages directly into legitimate Ledger and Trezor desktop applications on Windows…
The European Commission orders Google to give rival AI assistants the same hardware access as Gemini under the Digital Markets Act.
Symantec discovered Spirals, a Rust-based ransomware that encrypted an IT services company's network in less than a day.
Zoom fixed CVE-2026-53412, a critical account takeover vulnerability with a CVSS score of 9.8 affecting Windows users.
Cisco Talos uncovered a Russian-speaking threat actor using trojanized installers to deliver Starland RAT and memory-only implants.
Researchers discovered the NadMesh botnet, which targets exposed AI infrastructure to steal cloud keys and Kubernetes tokens.
A security researcher found that xAI's Grok Build CLI packaged and uploaded entire code repositories, including deleted secrets, to Google Cloud Storage.
Researchers discovered that malicious Chrome extensions can abuse a permission flaw in the Claude for Chrome extension to read Gmail without user consent.
Microsoft observed two ACR Stealer campaigns using fake error messages to trick users into running code that steals credentials and cloud session tokens.
The medical device giant confirmed unauthorized access to internal systems in its cancer diagnostics unit, which includes the recently acquired…
Artificial intelligence helped Microsoft discover and patch 570 security vulnerabilities in July, nearly tripling last month's record-breaking patch count.
CISA warns of active exploitation of CVE-2026-58644 and three other SharePoint flaws, urging federal agencies to patch within a week.
The TuxBot v3 Evolution botnet framework was built with help from an LLM, but the AI left a safety disclaimer…
The Treasury-led Gold Eagle program uses frontier AI models to accelerate vulnerability discovery and coordinated patching.
Checkmarx uncovered seven malicious npm packages targeting Vite developers with blockchain-based C2 infrastructure spanning Tron, Aptos, and Binance Smart Chain.
Sign in to your account