Amazon links the 2025 debug and chalk npm hijack to Sapphire Sleet with medium confidence, but does not show which evidence ...
Cisco FMC flaw CVE-2026-20316 is under active exploitation, letting unauthenticated attackers use static credentials to ...
Microsoft launches MAI-Cyber-1-Flash inside MDASH, routing up to 90% of tasks to the model while GPT-5.4 handles the hardest ...
CVE-2026-66066 could expose Rails server files through image uploads, leaking secrets that may enable RCE or lateral movement ...
A 2026 survey of 600 security leaders finds 73% of organizations are not fully ready for a major cyberattack, despite ...
Broadcom fixes two critical VMware vCenter flaws and a VMXNET3 ESX escape, with no evidence of exploitation in the wild.
A coordinated cyberattack targeted more than 30 Minnesota water systems, disrupting a plant and cellular links while ...
Russia charges Telegram founder Pavel Durov with aiding terrorist activity over channels it says were used to plan sabotage ...
Nebula says CVE-2026-10702 lets a malicious webpage compromise Tor Browser and start an Android 17 root chain.
A fraud campaign active since 2017 uses nearly 100 clone domains to steal advance payments from international B2B buyers.
The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are ...
Gitea fixes CVE-2026-60004, a 9.8 RCE that lets repository writers turn malicious patches into Git hooks and run commands.