A public exploit now exists for the Cisco IMC flaw that lets low-privilege users run commands as root.
VulnCheck found a phone-home implant in Zbtlink router firmware while the vendor called it a maintenance feature.
Huntress found attackers using Oracle's own Java engine to compile malware directly inside a database.
Maksim Silnikau, the Belarusian behind the Ransom Cartel ransomware service, received a 16-year prison sentence.
Meta confirmed one of its AI models breached a company during testing, the third AI lab escape disclosed in two…
Connor Riley Moucka admitted his role in the 2024 Snowflake raids that exposed records tied to more than 100 million…
Forescout's Vedere Labs built an attack chain from 15 flaws ending at the admin's cloud controller password.
Iran-linked actors are the leading suspects in a campaign that has hit at least 12 states since late July.
The charity CRM provider told customers to assume all stored data, including attachments, was downloaded.
Unit 42 details three ways malware can abuse Chrome's synced passkey flows to hijack accounts.
Langflow, N-able N-central, and Apache Tomcat flaws join the KEV catalog under active exploitation.
A 13-year-old memory corruption flaw ships with a public exploit covering roughly 800 kernel builds.
UK evaluators caught frontier models inventing personas and socially engineering a real open-source maintainer.
The Mini Shai-Hulud worm stole publisher credentials, republished tainted packages, and burrowed into AI coding tools.
The Police National Legal Database says contact details for officers and government staff surfaced on the dark web after an incident found July 26.
Attackers used an authentication bypass in N-able N-central to reach managed endpoints, and the vendor's first fix did not block the path.
A researcher used AI to alter DNA evidence files in about 45 minutes, prompting Thermo Fisher to add digital signatures across five product lines.
Three flaws in Hugging Face's Diffusers library let crafted model repositories run arbitrary code despite trust_remote_code protections.
River Financial Corporation told regulators it obtained assurances from the ransomware crew that breached it that stolen data was deleted.
The INC ransomware gang is the most active user of two exploited SonicWall SMA1000 flaws, adding victims across five countries…
OpenAI banned a coordinated network of ChatGPT accounts tied to Cambodian scam compounds that ran investment, romance and impersonation fraud.
Horizon3 raised $250 million in a Series E round that tripled its valuation to $2 billion, backing AI agents that…
A poisoned JavaScript file served by ad tech firm Adform rewrote crypto wallet addresses on customer sites.
Adobe patches a CVSS 10 Campaign Classic flaw that allows code execution with no user interaction.
Sign in to your account