WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under ...
Convex is not the only application backend on the market. According to the company, one of its platform’s main ...
Development environments have evolved into toolkits for directing coding models and coordinating agents. GitHub Copilot, ...
CryptoJS's weak RNG made recovery phrases guessable across five wallet apps, enabling Ill Bloom thefts totaling at least $5.69 million in two sweeps.
Typst is an easy and powerful markup-based language for creating technical documentation and books – and a compelling ...
FortiGuard exposes year-long QuickFox VPN supply chain attack deploying FDMTP implant on corporate Windows machines only.
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without ...
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals ...
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...