Containing fixes for critical-severity vulnerabilities, the monthly rollouts will focus on addressing priority issues faster.
Hi, what are you looking for?
Containing fixes for critical-severity vulnerabilities, the monthly rollouts will focus on addressing priority issues faster.
Dubbed Bleeding Llama, the heap out-of-bounds read issue can be exploited remotely, without authentication.
The most severe of these security defects could allow remote attackers to execute arbitrary code.
Deniss Zolotarjovs was directly involved in extortion strategies and in negotiations with victim companies.
The security defects allow unauthenticated, remote attackers to execute arbitrary code through crafted requests.
Hackers delivered malware via a customer chat channel, infected an analyst’s system, and accessed the internal support portal.
CISA has added the bug to its KEV list, and Microsoft has observed limited exploitation, mainly associated with PoC testing.
The attacks likely target CVE-2026-41940, a recently patched zero-day leading to administrative access.
Hackers disrupted services and stole names, email addresses, student ID numbers, and user messages.
Still under development, Bluekit provides users with automated domain registration and an AI Assistant.
The stealthy Python-based backdoor framework deploys a persistent Windows implant likely designed for espionage.
Threat actors are relying on social engineering to lure users into downloading files containing malicious instructions.
The compromised Lightning and Intercom packages have a combined monthly download count of nearly 10 million.
The bugs could be exploited to bypass security controls, access restricted services, and crash firewalls.
The Mini Shai-Hulud attack introduced a preinstall hook to fetch and execute a Bun binary and bypass security monitoring.
The authentication bypass flaw allows attackers to gain administrative access to vulnerable servers.
Affecting the kernel’s authencesn cryptographic template, the vulnerability was introduced in 2017 and impacts all distributions.
The vulnerability allows attackers to read data from a LiteLLM proxy’s database and potentially modify it.
The hackers exfiltrated the data from Checkmarx’s GitHub environment on March 30, a week after publishing malicious code.
US service members received WhatsApp messages claiming they would be targeted with drones and missiles.