Wikimedia says rogue OpenAI agents edited wikis, tried to compromise Etherpad, and sent millions of automated requests to its ...
Denmark says unauthorized parties accessed names, addresses, and CPR numbers for about 8.8 million people via a private ...
Google temporarily stops OSS VRP product vulnerability reports after a surge in automated submissions, most of which it says ...
A human-operated phishing platform impersonates AI ad tools to capture credentials and MFA codes through ...
Linux backdoors targeting South Korea and Taiwan disguise processes and traffic as trusted email services to evade detection.
Malicious spreadsheets can make LibreOffice and OpenOffice run Java code with Java enabled; LibreOffice has fixed the flaw.
FBI says a contractor failed to apply a security patch before a ShinyHunters breach stole personal details of thousands of employees.
Atlassian fixes a critical path traversal in 8 Data Center products that lets unauthenticated attackers read files if exact paths are known.
Microsoft observed ClickFix attacks using browser cache smuggling to execute cached VBScript and launch a credential-targeting malware chain.
OX found no marketplace vetting across 15,465 indexed MCP servers, including expired domains and hosts routed through consumer tunnels.
Microsoft patches CVE-2026-96940, which lets authenticated attackers read other users' Exchange mailboxes within the same ...
Apple plans tighter macOS Full Disk Access controls after AI agent use exposed risks to files, messages, mail, and browsing ...