Researchers found decade-old flaws in file-notification systems that let an unprivileged process infer what other users are doing.
A newly named threat actor automated a July Gitea flaw into a framework that stole source code and pushed on…
Researcher Zerotistic enrolls a Linux machine in Apple's Find My network and decrypts shared location data.
Trend Micro finds 14 trojanized packages that drop the RedC2 4.0 implant the moment they are imported.
GigaWiper is a modular Golang backdoor that merges remote access tools with disk wiping and fake ransomware capabilities.
A local attacker can exploit a page cache overflow in the Linux kernel's FUSE subsystem to gain root privileges by…
Four vulnerabilities in GNU Guix allow remote privilege escalation through malicious substitute servers and a path traversal in channel authentication.
Attackers hijacked over 400 abandoned Arch Linux AUR packages by modifying build scripts to deploy a Rust credential stealer and…