A compromise of Gyazo's upload servers handed attackers a database of account records and hundreds of millions of image identifiers.
A shared design weakness in the major coding agents lets hostile plugins run with the same reach as the developer…
Coast Guard and FBI teams found malicious activity on vessels hit while underway, exposing how much of a modern ship…
A small JavaScript stealer with fingerprints of North Korean developer-targeting campaigns has been found riding a cluster of malicious packages.
A new Android implant pairs itself to the device's own debugging daemon, then uses an AI-driven control loop to run…
Code running inside a sandboxed AI agent's virtual machine could read and rewrite files anywhere on the Mac that launched…
A workflow engine that many teams expose to the internet has been under active exploitation for a month, with no…
Check Point has shipped an emergency fix for a flaw that lets anyone on the network run code as root…
Cisco's identity appliance is being hit through an API endpoint that never checked who was asking.
A logic error below Android's reach lets attackers escalate on Pixel handsets without any interaction.
A signed banking token becomes the delivery vehicle for an implant that talks to its handlers over IoT messaging.
A signed security vendor binary carries an unsigned implant while blockchain smart contracts keep the command servers moving.
Honeytokens and fake credentials can raise the cost of an intrusion without a single new tool purchase.
A maintenance task ended with the model rewriting itself, and secrets and safety refusals went along for the ride.
An agent found a flaw, logged in and edited personal records without anyone directing it there.
A service that rented out denial-of-service floods for three years is offline, but the market it served is not.
A joint advisory from three governments exposes Chosen Brick, malware that turns ordinary chat apps into a surveillance pipeline aimed at activists and journalists.
JFrog researchers showed how one character in a crafted path turns a Parallels Desktop install into full control of a Mac.
A privilege escalation bug in Acronis backup extensions for cPanel and WHM is under limited, targeted attack against hosting infrastructure.
CenterPoint Energy confirmed a breach after a hacker said a poorly defended API let him pull millions of customer lines…
Attackers are bypassing JWT authentication in WSO2 middleware that banks, telcos, and governments rely on to broker API traffic.
Wordfence and Defiant detail critical flaws in WooCommerce Wholesale Lead Capture and The Events Calendar, both reachable without credentials.
Mandiant's enterprise AI report finds runaway agents, prompt injection, and weak access controls already costing real money.
A verified HBO Max Reddit account pushed 108 malicious ads in 48 hours, part of a broader operation spreading infostealers.