Group-IB details BraZetsu, a Python malware framework that stocks a paid marketplace with hacked Windows hosts.
OpenAI ships GPT-6 Astra after the model posts a perfect ExploitBench score and finds two zero-days in testing.
A 12-year-old PostgreSQL replication bug lets low-privilege backup accounts load code and become superusers.
Thomson Reuters says intruders took court case files in March, with Social Security numbers and sealed records possibly exposed.
A critical Nexus 9000 flaw leaves two TCP ports reachable and hands unauthenticated attackers root privileges.
Google patches the sixth Chrome zero-day of 2026 after attackers start exploiting a V8 type confusion bug.
ThreatFabric details StreamRat, an Android trojan pushed through fake TV streaming ads that can seize device control.
Symantec documents attackers abusing signed node.exe to run JavaScript payloads in intrusions since February.
A Russian man is extradited to face charges over Excel macro malware sent to roughly 80,000 freelancers.
A 46-country phishing wave leans on fake tax and shipping forms to push legitimate RMM tools, with the US the…
Manifold finds eight flaws where poisoned Git settings make seven AI coding agents run attacker commands.
Microsoft ties counterfeit download sites to Silver Fox as implants disable Windows Update and carve out Defender exclusions.
Researchers confirm Pegasus and a new NoviSpy variant hit at least 14 Serbian activists and students since January.
A new public exploit abuses CrowdStrike Falcon Sensor's macro cleanup routine to raise privileges on fully patched Windows.
Unauthenticated attackers can chain two GeoNetwork flaws into remote code execution on government geoportal servers.
The FBI warns OAuth consent phishing has been seizing prominent people's accounts since late 2025, and password resets do not stop it.
Kaspersky ties fake coding tests with a no-AI rule to two new Iranian RATs built for Windows, Linux, and macOS.
Attackers began hammering a critical Switchvox SQL injection weeks after the patch shipped, and exposed phone systems may all be in scope.
FBI agents opened an inquiry into an identity verification firm after a dark web shop began selling 153 million license…
Forescout guided Claude through a $536 exploit port between WAGO controllers, then watched a follow-up session brick the test PLC.
SonicWall confirms attackers are chaining two new SMA 1000 zero-days into remote code execution and urges immediate hotfixes.
US and European agencies sinkholed the 23-year-old Sality botnet by poisoning the peer lists its infected machines trust.
Five Venezuelan nationals pleaded guilty to failed ATM jackpotting attempts in Kansas, with one drawing nine months.
Aesto Health told HHS that 9.5 million people had personal and health data stolen from its AWS infrastructure.