China-linked Jewelbug uses XG-Web for espionage and crypto fraud, stealing over 580,000 browser cookies and thousands of ...
Apple alerts suspected mercenary spyware targets in 110 countries, expanding threat notifications that have reached users in ...
Trump memo directs NCC to let vetted U.S. firms conduct approved cyber surveillance and disruption operations against foreign ...
IAM compliance works only when organizations verify access controls across applications and infrastructure, not just document ...
Malicious LiteLLM PyPI releases stole cloud and SSH keys, Kubernetes tokens, and other secrets, potentially exposing 2,500+ ...
AmnesiaStealer uses a ClickFix lure to infect macOS, steal browser sessions, and give attackers live Chromium control via CDP.
WindRelay pairs with SpyNote to relay live NFC card data from infected Android phones, enabling contactless payment fraud in real time.
Attackers exploit SharePoint CVE-2026-55040 after a Rapid7 PoC release, forging JWTs to impersonate site users or admins.
Replayable AI reasoning blocks let researchers recover API keys and passwords from public logs; they say the main extraction attack is now mitigated.
APT36-linked hackers target Afghan telecom and Indian networks with new PATCHCORD and SHEETCORD backdoors using fake tools and Google Sheets for C2.
Adobe patches seven ColdFusion, Commerce, and Campaign Classic flaws that could enable code execution, privilege escalation, or denial-of-service.
Researchers hired three suspected North Korean IT workers into a fake crypto startup, exposing forged IDs, AI tools, VPNs, ...