Apple alerts suspected mercenary spyware targets in 110 countries, expanding threat notifications that have reached users in ...
IAM compliance works only when organizations verify access controls across applications and infrastructure, not just document ...
China-linked Jewelbug uses XG-Web for espionage and crypto fraud, stealing over 580,000 browser cookies and thousands of ...
Trump memo directs NCC to let vetted U.S. firms conduct approved cyber surveillance and disruption operations against foreign ...
Malicious LiteLLM PyPI releases stole cloud and SSH keys, Kubernetes tokens, and other secrets, potentially exposing 2,500+ ...
AmnesiaStealer uses a ClickFix lure to infect macOS, steal browser sessions, and give attackers live Chromium control via CDP.
Chrome VPN extensions with 75,486 installs route browser traffic through SOCKS5 proxies, putting the operator in an AitM position.
Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.
Attackers exploit SharePoint CVE-2026-55040 after a Rapid7 PoC release, forging JWTs to impersonate site users or admins.
ShieldBreak is a claimed patch bypass for Defender flaw CVE-2026-50656, with a PoC tested on Windows 11 25H2 and Server 2025.
APT36-linked hackers target Afghan telecom and Indian networks with new PATCHCORD and SHEETCORD backdoors using fake tools and Google Sheets for C2.
Adobe patches seven ColdFusion, Commerce, and Campaign Classic flaws that could enable code execution, privilege escalation, or denial-of-service.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results