A CVSS 9.5 Rails Active Storage flaw lets unauthenticated attackers read arbitrary server files through crafted image uploads.
Ruflo's unauthenticated MCP bridge earns a perfect CVSS 10 as researchers demonstrate AI memory poisoning.
CISA adds actively exploited Cisco FMC static credentials flaw to its known vulnerabilities catalog.
TA488 exploits OWA cross-site scripting flaw to plant browser implants that survive credential rotation.
DentaQuest is notifying over 23 million patients after the ShinyHunters extortion group stole 234 GB of data including Social Security…
Microsoft unveiled MAI-Cyber-1-Flash, its first specialized cybersecurity AI model, scoring 96% on CyberGym benchmarks and cutting vulnerability discovery costs by…
CI/CD platforms have become prime targets for attackers seeking supply chain access, and JetBrains’ latest security advisory underscores the risk.
Broadcom shipped emergency patches for a critical VM escape vulnerability affecting VMware ESXi, vCenter, and Fusion products.
A coordinated cyberattack targeted operational technology systems at more than 30 community water utilities across Minnesota.
Data security company Cyera agreed to acquire agentic access management provider Oasis Security in a $1 billion deal.
Threat actors compromised captive Wi-Fi gateways at hotels to silently redirect business travelers to fake Microsoft 365 login pages.
Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers to turn compromised systems into covert relay nodes across the Middle…
BlackFog researchers dissect MedusaHVNC, a remote access trojan that exploits Windows hidden desktops to hijack browser sessions and evade detection.
Researchers released a Certighost exploit for a critical AD CS flaw that lets authenticated users escalate privileges to full domain…
Group-IB discovered HOLLOWGRAPH, malware that uses Microsoft 365 calendars as covert command channels with events dated to 2050.
US agencies warn that Russian APT group Laundry Bear is actively exploiting CVE-2025-66376 against unpatched Zimbra Collaboration servers worldwide.
A vulnerability in OpenAI's ChatGPT workspace agent system could let attackers deploy malicious agents through a single phishing link.
Chinese AI agents from Kimi K3 autonomously found zero-day vulnerabilities in Redis and developed functional remote code execution exploits.
Attackers could achieve SYSTEM-level code execution on Bing servers by uploading crafted SVG files through two chained vulnerabilities.
Law enforcement seized hundreds of domains linked to a residential proxy service that turned smart TVs into botnet nodes for…
A pre-auth information leak combined with unauthenticated RCE in PTC products lets Cl0p affiliates steal intellectual property.
Alibaba's Fastjson 1.x library carries a critical deserialization flaw that attackers are exploiting in Spring Boot applications.
A malvertising campaign called SourTrade makes victims' browsers download and assemble malicious executables using a legitimate runtime.
Chick-fil-A disclosed a credential stuffing attack that compromised customer accounts in the Chick-fil-A One loyalty program.
Sign in to your account