Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure.
Hi, what are you looking for?
Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure.
Unauthenticated attackers can exploit the flaw via specially crafted POST requests that crash the Serv-U service.
Emphere’s solution delivers AI-driven remediation to software companies to speed up releases.
Raising $59 million to date, Opal also announced five senior leadership appointments.
The ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator.
Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws.
Posing as recruiters on online platforms, Chinese intelligence officers target personnel with access to classified or privileged information.
A flaw in the Full Page Cache Warmer extension can be exploited without authentication via serialized PHP object payloads.
Relying on social engineering, the hacking group engages in credential phishing, malware distribution, and fraud activities.
Law enforcement and tech companies disrupted infrastructure linked to scammers operating across Southeast Asia.
The high-severity flaw can be exploited remotely, without authentication, in server-side request forgery (SSRF) attacks.
Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.
The affected individuals’ personal information was stolen from a legacy server managed by a third party.
An improper authentication bug allows attackers to escalate their privileges and escape containers.
The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold.
A stack-based buffer overflow bug can be exploited for remote code execution on a vulnerable device.
Exploiting a confused deputy weakness, the hackers simply asked the chatbot to link the account to a new email address.
Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud.
Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster.
The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations.