Microsoft's 2026 report says attackers are reaping AI's speed gains faster than defenders can respond.
Sucuri's SC backdoor hides in eight places and rebuilds itself from any one that survives cleanup.
Longlegs and Storm-2603 keep breaching unpatched SharePoint servers to plant Warlock ransomware.
A China-aligned crew posed as a White House adviser and an economist to phish US AI policy experts.
Police seized KillSec's leak site and froze 110 terabytes of stolen data, detaining a 16-year-old they call its leader.
A 9.8-rated FortiMail flaw lets unauthenticated attackers write files, and the fix is still pending.
Truffle Security found more than half a million still-valid credentials exposed in public GitHub repositories.
The US Treasury has sanctioned the alleged developer of Tren de Aragua's ATM jackpotting malware and seven of his associates.
Google is handing a guardrail-free build of its newest frontier model, Gemini 4 Argon, to a small circle of vetted…
An AI-driven intruder chained two Zammad zero-days to climb from a helpdesk account to root in seconds.
Kevin Mandia's offensive security startup has raised $255.5 million in Series B funding, pushing its valuation past $2.5 billion.
CISA has ordered federal agencies to patch a critical Cisco SD-WAN Manager flaw that attackers are already exploiting.
With one AI firm disclosing agent risk to investors and another facing a hacking suit, liability for runaway models is…
OX Security says 101 packages abuse a WhatsApp library to sign victims' bot sessions up for groups they never chose.
Google and Mozilla pushed new builds fixing 32 Chrome flaws and roughly 76 Firefox bugs in a single day of browser patching.
A resend-timer mistake in OpenSSL's UDP handshake can hand leftover heap bytes to the other side of a DTLS session.
Glow Security traced thousands of internal images to AI coding agents that routed private screenshots through public repos.
Researchers show a practical Spectre v2 variant that harvests stale branch predictions left behind by just-in-time compilers.
A Kremlin-tied crew tied to the FSB is trading hand-aimed spear-phishing for bulk runs that plant its CosmicPulse backdoor.
Attackers pulled Polish national ID numbers from a clinic platform through a SQL injection flaw.
The Defense Manpower Data Center left unencrypted records open to intruders for nine months.
A malicious MCP server can redirect a client's OAuth handshake and pocket the secrets.
The toolkit let intruders hold ground inside telecom, university and government networks.
An out-of-bounds write in Apple's drawing engine was aimed at a targeted few.