Attackers use a fake browser popup that mimics Microsoft's OAuth login screen to steal credentials from unsuspecting users.
Researchers found that compromised assistive AI agents in Microsoft 365 can send malicious emails using a real user's permissions, evading…
MagicAd uses translucent activity windows to display ads without Android's overlay permission, and was found in over 50 apps on…
Two Russia aligned hacking groups continue to exploit a year old WinRAR vulnerability to deploy information stealing malware against Ukrainian…
Attackers have poisoned 19 PyPI packages with a new variant of a known supply chain malware that downloads the Bun…
The Apache Software Foundation released version 2.4.68 of its HTTP Server on June 8, 2026, patching 13 security vulnerabilities that…
CISA adds a Linux kernel privilege escalation flaw to its exploited vulnerabilities catalog, warning of active attacks targeting containerized environments.
The autonomous agent found vulnerabilities spanning multiple components including the VP9 decoder and RTMP client, with one critical flaw reachable…
Attackers are hiding behind Google's trusted DoubleClick ad infrastructure to route victims toward a fileless malware loader that runs entirely…
Google's Chrome 149.0.7827.53 stable release contains a record 429 vulnerability fixes including 22 critical severity bugs spanning GPU, networking, and…
The open source tool uses Windows' policy based quality of service to throttle EDR agent bandwidth to 8 bps, sidestepping detection methods used for traditional firewall blocking.
A use after free flaw in Linux kernel nftables enables local privilege escalation to root on Debian and Ubuntu systems.
Researchers discovered that the attacker waited 75 days after initial access before deploying a custom web shell framework designed to…
A critical authentication bypass in Check Point VPN products is being actively exploited, with attackers gaining network access without valid…
Attackers are chaining a LiteLLM command injection flaw with a Starlette authentication bypass to compromise AI gateway deployments without needing any credentials.
Meta uncovered NSO Group's attempt to bypass a permanent court order by launching a fresh phishing campaign on WhatsApp using malicious domains and test accounts.
A new side channel technique called FROST uses browser storage APIs and SSD timing measurements to identify which other applications and websites a user has open.
A single character error in the Linux kernel's nf_tables subsystem enables unprivileged users to gain root access and escape containers, with multiple working exploits now publicly available.
A Chinese cyber espionage group deployed a BSD variant of the BRICKSTORM backdoor on Linux appliances, infiltrating a victim's network…
A financially motivated threat group is using phone calls impersonating IT support and in person office visits to steal sensitive…
Apple's upcoming iOS 27 update will let its AI agentically replace compromised passwords across the Passwords app and Safari, marking…
The C0XMO botnet, a new variant of Gafgyt, exploits a DD-WRT router vulnerability and actively removes competing malware from infected…
The OWASP report provides security teams with a practical taxonomy and autonomy mapping framework for protecting AI agents that can…
Attackers hijacked a user account to breach Tchap, the French government's encrypted messaging app, stealing over 13GB of files and…
Sign in to your account