Grindr will pay £26M to settle a British lawsuit over pre-2020 data sharing with third parties, including HIV status information.
Google's newest AI Threat Tracker says extortion crews are stealing proprietary AI models and research, then demanding payment to keep…
The DFIR Report traces BengalSEO, an India-based search poisoning operation that has steered Bing users into scams and a miner-dropping…
CloudSEK says it reached the admin panel of a phishing service holding thousands of session cookies stolen from Microsoft 365…
SOCRadar details PEEP, a post-compromise toolkit that rides a fake bookmarks extension from the browser out to host-level command execution.
Two flaws chained together let a FreeIPA client that has never logged in plant a Kerberos identity into the administrators…
A Russian-language forum seller is offering what analysts call a genuine 32.8 million-account Conde Nast database tied to December's WIRED…
Nearly all of the Bitcoin backing Blockstream's Liquid sidechain has been drained, with the responsible hackers promising to return it…
Nightmare Eclipse adds Avast and Nvidia zero-day exploits to its CrowdStrike drop, and Gen says the Avast bug is fixed.
Check Point's static deobfuscation exposes JSCeal, a compiled V8 malware family that replays stolen cookies into Google accounts.
N-able's fourth N-central hotfix closes a CVSS 10 pre-auth RCE while its own advisories disagree on whether it is already exploited.
TantoSec's public tool turns a Telerik UI padding oracle into unauthenticated code execution for shops that skipped the July patch.
Three August lures ended in rogue ScreenConnect clients that spread a four-stage VBScript chain to every new host.
FulcrumSec dumped MAG airport customer data after the operator refused a ransom, exposing 8.8 million people.
JetBrains tells Cadence users to rotate all credentials after attackers breached its own cloud via unpatched TeamCity.
Researchers say OpenAI agents left roughly 18,000 posts on a dormant German wiki while coordinating on timed tasks.
Elastic finds four REVSTEALER companion modules that persist after the stealer deletes itself, including one that mines crypto.
An unpatched flaw named StyleSmuggler is letting attackers backdoor Magento and Adobe Commerce stores with no login.
CERT Polska warns that MikroTik routers with SSH exposed to the internet are being hijacked without any authentication.
Plex pushes security fixes for undisclosed flaws in Media Server 1.43.3 and Desktop 1.115.0.
Wordfence counts 440,000 exploit attempts against Super Forms and Elementor Pro file-upload flaws.
OpenAI pledges $1B in credits and training for under-resourced defenders through its Daybreak program.
HPE's AOS-CX updates close 34 CVEs including a 9.8-rated unauthenticated RCE cluster.
Microsoft tracks a phishing wave that splits lure words with invisible tag characters to dodge email filters.