A joint advisory from three governments exposes Chosen Brick, malware that turns ordinary chat apps into a surveillance pipeline aimed at activists and journalists.
JFrog researchers showed how one character in a crafted path turns a Parallels Desktop install into full control of a…
A privilege escalation bug in Acronis backup extensions for cPanel and WHM is under limited, targeted attack against hosting infrastructure.
CenterPoint Energy confirmed a breach after a hacker said a poorly defended API let him pull millions of customer lines…
Attackers are bypassing JWT authentication in WSO2 middleware that banks, telcos, and governments rely on to broker API traffic.
Wordfence and Defiant detail critical flaws in WooCommerce Wholesale Lead Capture and The Events Calendar, both reachable without credentials.
Mandiant's enterprise AI report finds runaway agents, prompt injection, and weak access controls already costing real money.
A verified HBO Max Reddit account pushed 108 malicious ads in 48 hours, part of a broader operation spreading infostealers.
Researchers built a cheap interposer that silently drops DDR5 writes and breaks the integrity guarantees behind confidential VMs.
A crafted message can give an unauthenticated attacker root on Cisco's secure email gateway, and the flaw is already being…
A recently patched Chrome and Windows exploit chain is now delivering two separate espionage toolsets against NGO targets.
A newly named threat actor automated a July Gitea flaw into a framework that stole source code and pushed on…
Attackers are hammering internet-facing Vite development servers to pull AWS and Azure credentials and infrastructure state files.
A shared platform serving 23 ministries was breached through an unpatched VPN, with disclosure coming 78 days after detection.
A flaw fixed in July left previously exported HTML chats able to run hidden JavaScript that copies messages to an attacker.
A government-linked Indian IT portal served a fake Cloudflare check that tried to get visitors to run a copied command.
A new AWS benchmark finds that AI models catch most real bugs but flag a huge share of safe code as vulnerable.
GOV.UK One Login is opening passkeys to more than 23 million users, letting them sign in without a password.
Canada's Telus says attackers used stolen credentials to reach customer records over more than a year.
A viewer add-on with tens of thousands of installs sent live Twitch session tokens to a commercial bot operator.
Firewall and proxy rules that allow the old addresses will need updating before early October.
A new Transportation Department rule lets carriers skip meal vouchers and hotels for cyberattack delays if they meet security rules.
Researchers blocked devices they never owned for under $4, exploiting six weaknesses in the lost and stolen phone system.
The commission withdrew a Biden-era statement that treated health and fitness apps as covered by federal breach notification rules.