Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
Hi, what are you looking for?
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass.
Hackers stole personal, medical, and health insurance information from a company’s data center.
The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws.
An attacker could self-register, sign in for board-level API access, and import a new company for code execution.
Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.
Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.
Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.
Hackers stole personal information, medical records, and financial information from the organization’s server.
AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects.
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
The company will use the investment to accelerate product innovation and expand go-to-market operations.
The AI security company will invest in product innovation, global expansion, and customer experience.
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent.
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
An extortion group stole personal, financial, and medical information from the hospital’s network.
The bank holding company was hacked in June, but the investigation into the incident continues.
The physical security firm says its alarm monitoring and system functionality have not been affected.
The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.