Eight malicious npm packages downloaded 40,767 times deliver Overlord RAT, a Node.js stealer, and a downloader to Windows ...
SonicWall fixed four SMA1000 flaws, including a 10.0-rated SSRF reachable before authentication; it says none are known to be ...
LMCache CVE-2026-105192 lets unauthenticated attackers run code when the multiprocess server is bound to a routable address; no fix exists.
Canto Incognito has infected over 3,400 servers, using exposed AI and LLM infrastructure for crypto mining and botnet growth.
FBI and USSS warn FortiBleed remains active, using stolen credentials and traffic sniffing to harvest Fortinet authentication data.
Attackers are exploiting an Atlassian Data Center flaw that enables unauthenticated access to specific webroot files.
Picus says agentic pentesting proves live attack paths but leaves timing and coverage gaps that require complementary validation methods.
Anthropic expands reduced-safeguard AI access for vetted cyber teams after Project Glasswing verified at least 129,000 ...
CERT-UA found 100+ compromised sites using ClickFix lures to distribute LunexStealer to Windows search visitors.
A human-operated phishing platform impersonates AI ad tools to capture credentials and MFA codes through ...
Linux backdoors targeting South Korea and Taiwan disguise processes and traffic as trusted email services to evade detection.
Malicious spreadsheets can make LibreOffice and OpenOffice run Java code with Java enabled; LibreOffice has fixed the flaw.