Two firms found independent ways to turn Atlassian's Rovo assistant into a one-click data leak.
Nearly 800 npm packages hide a cross-platform RAT and infostealer behind fake README instructions.
Google ties a vishing wave against finance and legal firms to UNC6671, which calls staff on personal phones.
WordPress ships an emergency fix for a pre-auth XSS chain that ends in PHP code execution.
Huntress documents a macOS ClickFix stealer that can drain crypto wallets and keychains.
A healthcare billing vendor says 3.8 million people's records were taken from its data center.
Attackers used an unknown Metabase flaw to grab admin access and customer data before a patch shipped.
Federal agencies have days to patch an exploited Progress ADC bug that drew hundreds of attack attempts.
A pre-auth XSS chain that needs only a crafted username ends in PHP code execution on stock installs.
Two research teams found ways to make Atlassian's AI assistant ship Jira and Confluence data to attacker servers.
Cisco's internal review with frontier AI models found 12 SD-WAN and IOS XE bugs, three rated 9.9.
Microsoft tracked a macOS ClickFix network that fingerprints visitors before serving its stealer lures.
A campaign of nearly 800 npm packages uses README lures and DNS tricks to deliver RATs on every platform.
DEF CON Franklin and NRWA launch Water Watch Center to bring managed detection and response to small water utilities.
NatJack attacks break the NAT trust model, letting same-network attackers hijack TCP sessions and poison DNS.
Zapscape, tracked as CVE-2026-64561, lets a nested KVM guest with kernel privileges escape to the host.
Tencent researchers escaped a container and reached host root through an 18-year-old SCTP use-after-free.
Swiss federal IT office BIT resets roughly 200 accounts after a Microsoft SharePoint credential theft.
A New Mexico judge brands Meta a public nuisance and orders $567M paid for child harm on its platforms.
Malware can borrow Windows Hello for Business keys to open a 90-day persistence channel into Entra ID.
A voicemail-themed AitM phishing wave is taking over Microsoft 365 accounts to harvest payroll and finance email.
CISA flags actively exploited TeamCity flaw CVE-2026-63077, giving federal agencies until August 8 to patch.
A public exploit now exists for the Cisco IMC flaw that lets low-privilege users run commands as root.
VulnCheck found a phone-home implant in Zbtlink router firmware while the vendor called it a maintenance feature.
Sign in to your account