Executive Order 14420 targets foreign bulk-power equipment over cyber, sabotage and supply-chain risks.
Microsoft tracks a ClickFix variant that drops a Python reverse tunnel through fake CAPTCHA overlays.
VulnCheck found two factory implants in ZBT router firmware that give unauthenticated attackers root access.
Socket found 19 Chrome and Edge extensions quietly stealing crypto wallet secrets in the Superior campaign.
OS-wide Encrypted Client Hello in Android 17 hides visited domains from carriers and Wi-Fi snoops.
Hunt.io found an exposed server packed with evidence of ownCloud and WordPress intrusions against Philippine targets.
A critical Cosmos EVM balance flaw let attackers drain six blockchains before the patch shipped.
Berlin refuses to pay after Rhysida-linked attackers exfiltrate data from the city's state network.
Vercel patches two critical unauthenticated RCE bugs in the Next.js framework.
Two independent flaws give attackers root on the G1 EDU, one over Bluetooth.
The US firearms bureau says intruders hit a standalone system tied to its investigations.
A critical cPanel and WHM bug turns authenticated tenants into server root users.
GPUThor flips bits in GDDR6 memory on four Ampere-class NVIDIA cards despite ECC.
Recorded Future ties a new batch-script backdoor to Russia's BlueDelta espionage group.
Manchester Airports Group says an extortion crew stole data tied to three UK airports.
Three maximum-severity bugs in the ServiceNow AI Platform can be exploited without authentication.
PaperCut Software confirmed active attacks on an unspecified vulnerability in its NG and MF print management products.
Troy Hunt's analysis found millions of synthetic records in the ShinyHunters Carhartt dump, cutting the real count to 12.9M.
OpenAI's report on the Hugging Face breach details how AI agents coordinated through internal systems to escape.
CISA added six actively exploited flaws to KEV, including a Citrix NetScaler bug now under attack in the wild.
CISA red team assessments fully breached two critical infrastructure organizations, and only the water utility noticed.
Australian police charged two Western Australian men over the TeamPCP syndicate's open-source supply chain attacks.
The FBI seized QScan and QTRouter, Chinese hacking platforms behind intrusions into NASA, the Federal Reserve, and the Senate.
A cyberattack that began August 25 disrupted Boston Scientific's IT systems and halted order processing worldwide.