A Chinese-speaking operation pulled configuration files and hashed root credentials from 996 Zyxel GS1900 switches before federal agencies got 72 hours to patch.
A malicious npm package pulled two million weekly downloads while running its payload from ordinary library code instead of an…
A PowerShell backdoor built from native Windows components steals business files, Wi-Fi passwords and clipboard contents while hiding as scheduled…
An anonymous commenter could plant a script that ran in an administrator's browser and, from there, uploaded a web shell…
A skipped cache invalidation leaves a freed page of host memory mapped and writable for a guest virtual machine on…
SpyCloud found 1,787 of roughly 10,000 US water organizations exposed, including one infected device holding logins for 167 utility tenants.
Microsoft scored the flaw 6.5 as a spoofing issue, while the National Vulnerability Database calls the same bug an 8.8…
A GitHub page posing as the LastPass Authenticator installs a Microsoft-signed kernel driver that terminates 145 security processes before a…
Ireland's regulator says Google's location processing broke GDPR rules and orders a six-month fix.
Fake recruiters are booking video calls with Rust maintainers and pushing malware.
Two Rust backdoors for Apple Silicon sat dormant on a developer's Mac for eleven days.
A new ransomware strain enters through VPN credentials and hides behind RMM agents.
CISA is retiring a weekly vulnerability bulletin it has published since 2004.
A rival crew says it now owns Clop's leak site and wants an eight-figure cut.
Two small Colorado water providers found control settings changed and alarms silenced.
Google's Gemini model attacked three real companies because one fictional target name matched a real domain, and the company stayed quiet about it for months.
Attackers used a long-lived Cloudflare API key stored in Brevo's own source code to push malware through the marketing platform's scripts to more than 100,000 websites.
CISA added three Linux kernel flaws to its exploited list while a researcher published working root exploits for four more.
Zscaler ThreatLabz tied four new tools, including a Rust backdoor that uses private GitHub repositories for command and control, to…
A year-old sealed plea became public this week when prosecutors moved to seize about $17.6M in crypto, vehicles and luxury…
ESET found the SparroWocky backdoor in government networks across eight Latin American countries as the group shifted 90 percent of…
A single extension holding two common permissions could command the built-in AI in Chrome, Comet, Edge, Opera Neon and Claude…
SolarWinds has patched a hard-coded key that let unauthenticated attackers run code in Access Rights Manager.
Hacktron used Claude Opus 5 to exploit a libheif memory bug, then walked through OpenAI's single sign-on into staff accounts.