US agencies warn that Russian APT group Laundry Bear is actively exploiting CVE-2025-66376 against unpatched Zimbra Collaboration servers worldwide.
A vulnerability in OpenAI's ChatGPT workspace agent system could let attackers deploy malicious agents through a single phishing link.
Chinese AI agents from Kimi K3 autonomously found zero-day vulnerabilities in Redis and developed functional remote code execution exploits.
Attackers could achieve SYSTEM-level code execution on Bing servers by uploading crafted SVG files through two chained vulnerabilities.
Law enforcement seized hundreds of domains linked to a residential proxy service that turned smart TVs into botnet nodes for…
A pre-auth information leak combined with unauthenticated RCE in PTC products lets Cl0p affiliates steal intellectual property.
Alibaba's Fastjson 1.x library carries a critical deserialization flaw that attackers are exploiting in Spring Boot applications.
A malvertising campaign called SourTrade makes victims' browsers download and assemble malicious executables using a legitimate runtime.
Chick-fil-A disclosed a credential stuffing attack that compromised customer accounts in the Chick-fil-A One loyalty program.
A ransomware-as-a-service platform called DevMan offers a centralized web dashboard for payload generation and victim management.
Europol identified thousands of horrific URLs linked to The Com network as part of an ongoing crackdown on the violent extremist youth group.
A newly patched Active Directory flaw let standard domain users impersonate domain controllers and forge authentication tokens.
Researchers found flaws in Microsoft's Bing Images service allowing crafted SVG files to execute arbitrary commands as SYSTEM on internal…
A race condition in Ubuntu's Snap sandbox initialization, tracked as CVE-2026-8933, lets local attackers escalate privileges to root on default…
A vulnerability chain in the Adobe Acrobat Chrome extension let any webpage silently steal WhatsApp Web chats from 329 million browsers without malware.
Google DeepMind released Gemini 3.5 Flash Cyber, a specialized AI for vulnerability hunting, restricted to governments and trusted partners due to dual-use risks.
Check Point patched a critical SmartConsole authentication bypass under active exploitation that gives attackers full admin access to security management servers.
A trojanized Newtonsoft.Json fork on NuGet smuggles game-rigging malware inside a fully functional serialization library to evade detection.
OpenAI and Anthropic models broke rules in cybersecurity tests and failed to admit it, with cheating rates between 7.8% and…
Have I Been Pwned confirms the massive breach of the AI music platform, including email addresses and partial credit card…
CVE-2026-6875 lets attackers bypass the ServiceNow script sandbox through a JavaScript override technique, with exploitation already in the wild.
German and US law enforcement seized 200 servers and arrested the alleged developer of the Kratos phishing platform in Indonesia.
Attackers are exploiting a critical SharePoint RCE vulnerability to steal machine keys, and patching alone won't lock them out.
A large-scale supply chain attack dubbed FakeGit uses thousands of deceptive GitHub repositories to distribute SmartLoader malware.
Sign in to your account