ShinyHunters says an Oracle PeopleSoft zero-day put it inside the FBI jobs portal, and it wants a retraction rather than a ransom.
Microsoft has seized the infrastructure behind a phishing kit that used AI to pick its victims, and two suspects are…
A path traversal bug in Check Point's management plane was already being used against customers weeks before the vendor knew…
A heap overflow in BIG-IP APM hands unauthenticated attackers code execution on any appliance serving as an OAuth authorization server.
A CVSS 10.0 input validation bug in on-premises VeloCloud Orchestrator is under active exploitation, and fixes cover only two of…
Volexity has linked a China-aligned group to a three-bug Chrome and Windows chain that ran before either vendor shipped a…
WordPress 7.1.2 closes a path traversal in get_page_template() that needs no account and can end in code execution on some…
A Chinese-speaking operation pulled configuration files and hashed root credentials from 996 Zyxel GS1900 switches before federal agencies got 72…
A malicious npm package pulled two million weekly downloads while running its payload from ordinary library code instead of an…
A PowerShell backdoor built from native Windows components steals business files, Wi-Fi passwords and clipboard contents while hiding as scheduled…
An anonymous commenter could plant a script that ran in an administrator's browser and, from there, uploaded a web shell to the site.
A skipped cache invalidation leaves a freed page of host memory mapped and writable for a guest virtual machine on…
SpyCloud found 1,787 of roughly 10,000 US water organizations exposed, including one infected device holding logins for 167 utility tenants.
Microsoft scored the flaw 6.5 as a spoofing issue, while the National Vulnerability Database calls the same bug an 8.8…
A GitHub page posing as the LastPass Authenticator installs a Microsoft-signed kernel driver that terminates 145 security processes before a password stealer runs.
Ireland's regulator says Google's location processing broke GDPR rules and orders a six-month fix.
Fake recruiters are booking video calls with Rust maintainers and pushing malware.
Two Rust backdoors for Apple Silicon sat dormant on a developer's Mac for eleven days.
A new ransomware strain enters through VPN credentials and hides behind RMM agents.
CISA is retiring a weekly vulnerability bulletin it has published since 2004.
A rival crew says it now owns Clop's leak site and wants an eight-figure cut.
Two small Colorado water providers found control settings changed and alarms silenced.
Google's Gemini model attacked three real companies because one fictional target name matched a real domain, and the company stayed…
Attackers used a long-lived Cloudflare API key stored in Brevo's own source code to push malware through the marketing platform's…