Vercel patches two critical unauthenticated RCE bugs in the Next.js framework.
Two independent flaws give attackers root on the G1 EDU, one over Bluetooth.
The US firearms bureau says intruders hit a standalone system tied to its investigations.
A critical cPanel and WHM bug turns authenticated tenants into server root users.
GPUThor flips bits in GDDR6 memory on four Ampere-class NVIDIA cards despite ECC.
Recorded Future ties a new batch-script backdoor to Russia's BlueDelta espionage group.
Manchester Airports Group says an extortion crew stole data tied to three UK airports.
Three maximum-severity bugs in the ServiceNow AI Platform can be exploited without authentication.
PaperCut Software confirmed active attacks on an unspecified vulnerability in its NG and MF print management products.
Troy Hunt's analysis found millions of synthetic records in the ShinyHunters Carhartt dump, cutting the real count to 12.9M.
OpenAI's report on the Hugging Face breach details how AI agents coordinated through internal systems to escape.
CISA added six actively exploited flaws to KEV, including a Citrix NetScaler bug now under attack in the wild.
CISA red team assessments fully breached two critical infrastructure organizations, and only the water utility noticed.
Australian police charged two Western Australian men over the TeamPCP syndicate's open-source supply chain attacks.
The FBI seized QScan and QTRouter, Chinese hacking platforms behind intrusions into NASA, the Federal Reserve, and the Senate.
A cyberattack that began August 25 disrupted Boston Scientific's IT systems and halted order processing worldwide.
Norway's shared government infrastructure takes its third DDoS hit in months, disrupting login services nationwide.
Two new Windows trojans pull their next commands straight from FTP server banners in a first-seen delivery trick.
CISA counts over 100 internet-exposed water systems targeted in July and urges utilities to shrink their attack surface.
OpenAI cuts off ChatGPT accounts running a Russian influence campaign behind a fake think tank.
A malicious webpage can hijack the local AI behind NVIDIA NemoClaw and plant hidden instructions in the model.
A phishing service rents AI voice agents posing as Apple support to harvest passcodes and unlock stolen iPhones.
An eight-month INTERPOL push against West African cybercrime ends with 58 arrests and 263 suspects identified.
CISA flags a critical Gitea code injection bug that attackers are using to drop crypto miners on exposed servers.