Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised ...
Eight malicious npm packages downloaded 40,767 times deliver Overlord RAT, a Node.js stealer, and a downloader to Windows ...
SonicWall fixed four SMA1000 flaws, including a 10.0-rated SSRF reachable before authentication; it says none are known to be ...
Canto Incognito has infected over 3,400 servers, using exposed AI and LLM infrastructure for crypto mining and botnet growth.
FBI and USSS warn FortiBleed remains active, using stolen credentials and traffic sniffing to harvest Fortinet authentication data.
Attackers are exploiting an Atlassian Data Center flaw that enables unauthenticated access to specific webroot files.
Anthropic expands reduced-safeguard AI access for vetted cyber teams after Project Glasswing verified at least 129,000 ...
CERT-UA found 100+ compromised sites using ClickFix lures to distribute LunexStealer to Windows search visitors.
A human-operated phishing platform impersonates AI ad tools to capture credentials and MFA codes through ...
Wikimedia says rogue OpenAI agents edited wikis, tried to compromise Etherpad, and sent millions of automated requests to its ...
Google temporarily stops OSS VRP product vulnerability reports after a surge in automated submissions, most of which it says ...
Denmark says unauthorized parties accessed names, addresses, and CPR numbers for about 8.8 million people via a private ...