The Sleepwalker backdoor waits in memory for one magic packet, then runs commands in its own language.
Broadcom's Spring framework patches 91 flaws in one release, including a critical LDAP bug.
One approved MFA push gave ShinyHunters-linked callers a brief view-only session inside ReliaQuest.
Sponsored ads route Mac developers to fake Codex pages that end in a malicious Terminal command.
Two unauthenticated bugs in the miniOrange SAML plugin let attackers log in as any WordPress user.
Fake Minecraft client sites keep ranking at the top of search results while dropping the WeedHack infostealer.
A two-year phishing-as-a-service campaign bypasses 2FA across more than 4,500 Microsoft 365 domains.
CISA adds a CVSS 10.0 Oracle WebLogic flaw to its exploited list and gives federal agencies a three-day patch window.
Red Hat patches a critical Keycloak flaw that lets unauthenticated attackers seize any account, including admins.
GuidePoint finds a sham firm called Ransom Busters billing victims for recoveries it likely cannot deliver.
Researcher Zerotistic enrolls a Linux machine in Apple's Find My network and decrypts shared location data.
Kyle Spitze, an original 764 member, draws the longest federal sentence yet imposed on a nihilistic violent extremist.
Slovakia's NBU warns that NERO R-ONE road cameras carry serious cyber risks, from data exposure to remote access.
Seqrite Labs tracks Operation QUICSILVER, a China-nexus espionage push that delivers a QUIC-based Go implant to Myanmar targets.
Cisco Talos details UAT-10147, a Chinese-speaking crew that leans on AI tooling and a new SPECTRE implant to hit web servers.
A new phishing kit enrolls attacker passkeys to keep access after password resets.
LockBit lists US Bank on its leak site, but the lender says the claim traces to a vendor event.
A $25 template underpins hundreds of fake banking sites built for fraud, Allure Security finds.
Researchers leaked a JWT from a co-located Cloudflare Worker via Spectre at 12 bits per second.
New research shows CDN protocol conversion can amplify a low-bandwidth attack stream up to 350x at the origin.
Iran-linked hackers knocked a small UK power plant offline for four days, The Telegraph reports.
TikTok will pay $400M to end a US lawsuit over child privacy violations, the Justice Department announced.
The private equity giant says attackers hit its cloud platforms in July, exposing names and Social Security numbers.
Two exploited TrueConf Server flaws land on CISA's KEV list as Head Mare is caught delivering a poisoned installer.