Attackers exploit a JFrog Artifactory authentication bypass to mint admin tokens and enumerate users on default ...
Breeze Comet targets Brazilian payment systems with custom malware, compromised accounts, and hundreds of fraudulent ...
Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
Attackers stole a METR API key and consumed credits worth about $600,000, while a later campaign failed to access internal ...
ValleyRAT abuses signed QN Wallpaper software for DLL sideloading, disables Windows Defender, and runs inside a trusted ...
DoJ corrected its QTFY statement, saying several U.S. agencies were targets rather than confirmed victims of the China-linked ...
North Korean workers are expanding remote-job fraud beyond IT into healthcare and sales, using false identities, proxies, and ...
This week’s cybersecurity recap covers AI agents breaching Hugging Face, Chinese spy proxies, router backdoors, PaperCut ...
Aurora ransomware operators used Cursor Agent for hands-on exploitation against 10 targets after receiving credentials or an ...
Fire Ant compromises Cisco IOS XR routers and TACACS servers to capture traffic, harvest credentials, and suppress defensive ...
Critical flaws in WPMU DEV, Avada, TranslatePress, Pods, and GiveWP can enable admin takeover or remote code execution.
Two unpatched Kaltura mwEmbed flaws allow unauthenticated file read and could enable RCE through unsafe deserialization.