Two former executives of a call tracking company admitted to providing phone numbers and coaching to tech support scammers based in India.
The campaign abused legitimate signed binaries from Fortemedia and SentinelOne to bypass security detection while targeting industrial, financial, and transportation…
A new iPhone feature in development uses accelerometer and Apple Watch signals to automatically lock the screen the moment the…
A zero click attack exploits two vulnerabilities to silently hijack WhatsApp accounts on iOS 16 devices, leaving no trace in…
Recent supply chain attacks demonstrate a clear shift from code injection to credential theft, targeting developer environments as a primary…
Ubiquiti releases emergency patches for three maximum severity flaws in UniFi OS that allow unauthenticated remote attackers to compromise systems.
The convenience store chain disclosed that attackers accessed franchisee document systems in April, leading to the exposure of hundreds of…
Agentic AI transforms Network Detection and Response by autonomously correlating high data volumes to surface hidden threats, freeing analysts from…
Attackers used an outdated F5 BIG-IP load balancer as an initial entry point to gain SSH access to a Linux…
A high severity flaw in ConnectWise Automate's plugin loading mechanism could allow network based attackers to run malicious code without…
Technical signals and internal documents suggest Anthropic is preparing to offer its previously restricted Claude Mythos AI model through Claude Code and a new enterprise security dashboard.
Attackers are actively exploiting a critical NGINX buffer overflow vulnerability that can crash worker processes and potentially enable remote code…
Attackers exploit human psychology by flooding users with push notifications until they accidentally approve a login request, bypassing the security…
Ivanti, Fortinet, SAP, VMware, and n8n have released critical security patches addressing remote code execution, SQL injection, and authentication bypass…
CERT-In's new 12 hour patching mandate for internet facing systems aims to counter the rising threat of AI driven automated cyberattacks.
Phishing services are exploiting encrypted messaging protocols like RCS and iMessage to bypass traditional carrier filters that block malicious SMS links.
The open source Pentest Agent Suite brings a validator gate and persistent memory tracker to automate vulnerability discovery across seven AI coding platforms.
The Payload ransomware uses per file ChaCha20 encryption with Curve25519 key exchange and aggressively deletes backups and logs before locking systems.
A buffer overflow in 7-Zip's NTFS handler allows attackers to hijack program execution simply by tricking a user into opening…
Mandiant discovered attackers exploiting a shared ASP.NET machine key flaw in KnowledgeDeliver LMS to deploy the BLUEBEAM in-memory web shell.
An Iranian state linked group used search engine optimization tricks to rank a fake SQL Developer download page at the…
The malware associated with the Void Dokkaebi threat actor now uses Cython to compile Python code into binary .pyd and…
A novel attack called Underminr exploits shared CDN architecture to route malicious traffic through trusted domains, potentially exposing over 88…
Cloud Atlas modifies the Windows termsrv.dll file to bypass RDP session limits, enabling stealthy simultaneous access with legitimate users.
Sign in to your account