Plex pushes security fixes for undisclosed flaws in Media Server 1.43.3 and Desktop 1.115.0.
Wordfence counts 440,000 exploit attempts against Super Forms and Elementor Pro file-upload flaws.
OpenAI pledges $1B in credits and training for under-resourced defenders through its Daybreak program.
HPE's AOS-CX updates close 34 CVEs including a 9.8-rated unauthenticated RCE cluster.
Microsoft tracks a phishing wave that splits lure words with invisible tag characters to dodge email filters.
Rapid7 finds a North Korea-linked toolkit hiding inside trojanized HAProxy builds at two South Korean firms.
Broadcom's 26H1u1 update closes two guest-to-host escape bugs with no workarounds available.
Group-IB details BraZetsu, a Python malware framework that stocks a paid marketplace with hacked Windows hosts.
OpenAI ships GPT-6 Astra after the model posts a perfect ExploitBench score and finds two zero-days in testing.
A 12-year-old PostgreSQL replication bug lets low-privilege backup accounts load code and become superusers.
Thomson Reuters says intruders took court case files in March, with Social Security numbers and sealed records possibly exposed.
A critical Nexus 9000 flaw leaves two TCP ports reachable and hands unauthenticated attackers root privileges.
Google patches the sixth Chrome zero-day of 2026 after attackers start exploiting a V8 type confusion bug.
ThreatFabric details StreamRat, an Android trojan pushed through fake TV streaming ads that can seize device control.
Symantec documents attackers abusing signed node.exe to run JavaScript payloads in intrusions since February.
A Russian man is extradited to face charges over Excel macro malware sent to roughly 80,000 freelancers.
A 46-country phishing wave leans on fake tax and shipping forms to push legitimate RMM tools, with the US the top target.
Manifold finds eight flaws where poisoned Git settings make seven AI coding agents run attacker commands.
Microsoft ties counterfeit download sites to Silver Fox as implants disable Windows Update and carve out Defender exclusions.
Researchers confirm Pegasus and a new NoviSpy variant hit at least 14 Serbian activists and students since January.
A new public exploit abuses CrowdStrike Falcon Sensor's macro cleanup routine to raise privileges on fully patched Windows.
Unauthenticated attackers can chain two GeoNetwork flaws into remote code execution on government geoportal servers.
The FBI warns OAuth consent phishing has been seizing prominent people's accounts since late 2025, and password resets do not…
Kaspersky ties fake coding tests with a no-AI rule to two new Iranian RATs built for Windows, Linux, and macOS.