New forensic details reveal how threat actors leveraged a Cisco SD-WAN zero-day vulnerability to create hidden root accounts, establish persistent access, and erase traces of compromise across targeted enterprise networking environments.
Google is rolling out new account settings that separate search activity history from personalization preferences, giving users greater control over…
A sophisticated attack chain dubbed Edgecution is abusing Microsoft Edge extensions and Chrome Native Messaging to bypass browser security boundaries,…
Threat actors have begun exploiting Cisco Unified Communications Manager vulnerability CVE-2026-20230, a critical file-write flaw that can ultimately lead to…
Healthcare AI company Xolis has disclosed a phishing-driven breach that exposed sensitive personal and medical data belonging to approximately 1.4…
LastPass has confirmed that attackers used stolen OAuth tokens from a Klue supply chain breach to access Salesforce support case…
A new macOS ClickFix campaign is tricking users into running Terminal commands that silently download and mount malicious DMG files…
CISA has warned that multiple high-severity vulnerabilities in Ubiquiti UniFi OS and Lantronix EDS5000 devices are being actively exploited, prompting…
A newly identified stealth backdoor called Mistic has been linked to the KongTuke initial access broker and is being used…
GitHub has updated actions/checkout to block common fork-based “pwn request” attack patterns in pull_request_target workflows, reducing the risk of malicious…
A new executive order establishes firm deadlines for U.S. federal agencies and contractors to transition to post-quantum cryptography, accelerating national security efforts to defend against future quantum-enabled decryption threats.
Security researchers have uncovered malicious npm packages posing as PostCSS utilities that deploy a multi-stage Windows remote access trojan capable…
Tata Electronics has acknowledged a cybersecurity incident affecting parts of its IT environment after a cyber extortion group claimed responsibility…
Researchers demonstrated how a seemingly legitimate AI agent skill bypassed multiple security scanners and reportedly spread to thousands of agents…
Researchers have uncovered a massive credential-harvesting operation dubbed 'FortiBleed' that leveraged compromised FortiGate firewalls and automated cracking infrastructure to collect more than 110 million credentials worldwide.
Security researchers have detected active exploitation of a critical Cisco Unified Communications Manager vulnerability that can allow attackers to write files to vulnerable systems and potentially escalate privileges to root…
The U.S. government has seized cloud infrastructure linked to the Huione ecosystem and imposed new sanctions targeting entities connected to Southeast Asia's sprawling cyber fraud and money laundering operations.
Researchers have uncovered a dangerous CI/CD workflow weakness dubbed "Cordyceps" that could allow unauthenticated attackers to hijack repositories, steal credentials, and compromise software supply chains across hundreds of major open-source…
An international law enforcement operation has disrupted the infrastructure behind the Amadey and StealC malware ecosystems, seizing hundreds of servers…
CISA has added a critical Lantronix EDS5000 vulnerability to its Known Exploited Vulnerabilities catalog after confirming active attacks, while also…
A large npm supply chain compromise affecting over 140 Mastra AI packages has been linked to the North Korean threat…
A new ransomware strain dubbed Prinz Eugen is prioritizing recently modified files for encryption while avoiding ransom notes entirely, signaling…
Attackers are exploiting a medium-severity Gravity SMTP plugin vulnerability to extract sensitive configuration data, including API keys and OAuth tokens,…
The world's largest international police organization warns of a dramatic rise in phishing, ransomware, and AI-enabled scams across Asia and…
Sign in to your account