Google patched an actively exploited Chrome V8 flaw that enables arbitrary code execution inside the sandbox through a ...
OpenAI limits GPT-6 Astra to code review and patching after tests showed exploit development capabilities, including two zero ...
This week’s ThreatsDay Bulletin tracks fake IT calls, abused remote tools, phishing kits, unsafe downloads, ransomware, ...
Thomson Reuters says an unauthorized party obtained C-Track court files that may contain personal and sealed information.
Cisco patches a Nexus 9000 flaw enabling unauthenticated remote root code execution and seven IOS XR umbrella CVEs affecting ...
Attackers abuse Node.js to execute malicious scripts and deploy payloads in attacks targeting governments, technology ...
An iMessage zero-click exploit infected a Serbian student movement member's iPhone with Pegasus spyware in December 2025 and ...
Shai-Hulud now scans 469 locations for credentials across developer environments, CI/CD tooling, cloud configs, and AI tool ...
A phishing campaign uses fake documents to install legitimate RMM software across 46 countries, with 45% of activity tied to ...
FalconFlank abuses CrowdStrike Falcon's malicious macro remediation to demonstrate local privilege escalation on updated ...
CISA adds seven exploited flaws affecting SonicWall, Artifactory, Switchvox, Starlette, Kestra, and LiteLLM to its KEV ...
Bogus software download sites deploy malware that weakens Windows defenses and establishes persistence in China-based ...