Researchers show Loongson cache flaws leak kernel keys across VM boundaries.
The extortion group linked to BlackFile successors says it stole nearly 1M files.
Malwarebytes finds a lookalike CCleaner site pushing a Chrome credential stealer.
A fresh round of Apple mercenary spyware warnings lands in 110 countries.
Group-IB links WindRelay and SpyNote in real-time card fraud across Europe.
Attackers are exploiting CVE-2026-65400 to drop Monero miners on exposed Macs.
France's DGFiP confirms a June intrusion that exposed taxpayer data.
ShinyHunters dumped account data after RingCentral refused an extortion demand.
Jamf Threat Labs details a three-stage Rust stealer that harvests macOS credentials and gives operators live, hidden control of the…
A free archive with 7.3 million Chess.com records looks like large-scale scraping, though one internal-facing detail needs explaining.
watchTowr logged hundreds of exploitation probes against an unpatched GeoServer SQLi bug within hours of its disclosure.
Huntress says an Akira affiliate rebooted a victim into Safe Mode to kill EDR, then the encryptor crashed on the…
Sansec blocked the first exploits of CVE-2026-71362, an unauthenticated account takeover in Adobe Commerce rated 9.1.
Trellix found dark web services like APEX AI and MessiahGPT that lower the skill bar for ransomware-grade attacks.
A breach at shipping partner ShipMonk exposed names, emails and addresses for over 13,000 Trezor customers.
CERT-UA ties fake recruiter lures to Sandworm subgroup UAC-0145, which hides PowerShell execution inside a poisoned WireGuard client.
Socket finds 737 VPN and proxy add-ons funneling browser sessions through a single provider.
Reco tracks a long-running campaign harvesting records from over-permissioned SaaS portals.
A July cyberattack on CEVA Logistics halted shipments and exposed customer details for Valve and others.
A new White House program would let private firms run offensive operations under federal oversight.
Israeli firm Dream documents what appears to be the first autonomous AI attack on a government.
A researcher's ShieldBreak PoC claims to bypass Microsoft's fix for the Defender RoguePlanet flaw.
Check Point ties a Windows zero-day to Lazarus attacks on defense firms using fake job offers.
Attackers are exploiting a critical SharePoint authentication bypass days after Rapid7 shipped proof-of-concept code.
Sign in to your account