The zero-day was designed to bypass 2FA and it was developed by a prominent cybercrime group.
Hi, what are you looking for?
The zero-day was designed to bypass 2FA and it was developed by a prominent cybercrime group.
The company topped revenue and earnings forecasts for the first quarter of 2026, but its shares plunged more than 20%.
Also called Copy Fail 2 and tracked as CVE-2026-43284 and CVE-2026-43500, the exploit was disclosed before a patch was released.
The hackers gained the ability to modify equipment operational parameters, creating a direct risk to the public water supply.
RansomHouse has published several screenshots to demonstrate access to internal Trellix services.
CVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code.
The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was.
Cisco’s AI security researchers have analyzed ways to target vision-language models (VLMs) using pixel-level perturbation.
Dragos has published a report describing how threat actors used Claude AI in an attack on a water and drainage utility in Mexico.
Gavril Sandu, 53, was indicted in 2017, but was arrested and extradited to the United States only in 2026.
Agency issued guidance and calls on operators to build resilient OT environments capable of surviving extended isolation and cyber compromise.
CVE-2026-0300 affects the Captive Portal service of PAN-OS software on PA and VM series firewalls.
The malicious emails claim to contain a conduct report and lure victims to a Microsoft phishing website that leverages AitM.
CVE-2026-0073 affects Android’s System component and it can be exploited without any user interaction.
The vulnerabilities were reported to Meta through its bug bounty program and were patched with updates released earlier this year.
The cybersecurity firm’s investigation has not found any impact on its source code release or distribution process.
Significant cybersecurity M&A deals announced by Airbus, Cyera, Fortra, Palo Alto Networks, Silverfort, and Socket.
Advanced Account Security provides stronger login methods, more secure account recovery, shorter sessions, and training exclusion.
The maximum reward for a zero-click Pixel Titan M exploit with persistence has increased to $1.5 million.
Ryan Goldberg of Georgia and Kevin Martin of Texas were each sentenced to four years in prison.