A June intrusion at the medical equipment network reached patient and insurance data.
Washington took down Xinbi Guarantee's Telegram channels and froze $52.8M in stablecoin.
Thousands of exposed AI gateways accept the demo key printed in LiteLLM's setup guide.
A fresh proof of concept says Microsoft's fix for a Defender escalation bug leaves a gap.
A new exploit kit chained two Chrome flaws and a Windows bug for four espionage crews.
A widened transcript scan turned up another incident of a model reaching a third party.
Three exploited networking flaws now carry a three-day federal patch deadline.
CrowdStrike details Slim Spider, a Brazil-based group stealing crypto custody secrets from financial clouds.
SAP patches OVERPASS, a CVSS 10 kernel bug that lets unauthenticated attackers run commands on SAP hosts.
Check Point shows a planted instruction can make ChatGPT exfiltrate Gmail data through a covert channel between accounts.
NSA, CISA and FBI accuse China-based AI labs of industrial-scale distillation of US frontier model capabilities.
A fileless rootkit dubbed PoisonedRefresh injects PHP web shells into the memory of compromised F5 BIG-IP APM appliances.
Researchers built a zero-click worm, dubbed WeWorm, that takes over WeChat accounts through incoming calls before Tencent's August fix.
Chrome 153 closes an out-of-bounds write in V8 that Google says is exploited in the wild, the browser's seventh zero-day…
September's Patch Tuesday set a record with 974 fixes, two exploited zero-days and a cluster of potentially wormable bugs.
Grindr will pay £26M to settle a British lawsuit over pre-2020 data sharing with third parties, including HIV status information.
Google's newest AI Threat Tracker says extortion crews are stealing proprietary AI models and research, then demanding payment to keep them private.
The DFIR Report traces BengalSEO, an India-based search poisoning operation that has steered Bing users into scams and a miner-dropping backdoor since 2015.
CloudSEK says it reached the admin panel of a phishing service holding thousands of session cookies stolen from Microsoft 365…
SOCRadar details PEEP, a post-compromise toolkit that rides a fake bookmarks extension from the browser out to host-level command execution.
Two flaws chained together let a FreeIPA client that has never logged in plant a Kerberos identity into the administrators…
A Russian-language forum seller is offering what analysts call a genuine 32.8 million-account Conde Nast database tied to December's WIRED…
Nearly all of the Bitcoin backing Blockstream's Liquid sidechain has been drained, with the responsible hackers promising to return it…
Nightmare Eclipse adds Avast and Nvidia zero-day exploits to its CrowdStrike drop, and Gen says the Avast bug is fixed.