The campaigns focus on financial organizations, including cryptocurrency, venture capital, and blockchain entities.
Hi, what are you looking for?
The campaigns focus on financial organizations, including cryptocurrency, venture capital, and blockchain entities.
The company released 481 new security patches across 28 product families, including over 300 fixes for remotely exploitable, unauthenticated flaws.
Masquerading as popular cryptocurrency wallets, the apps can hijack recovery phrases and private keys.
The security defects could be exploited for remote code execution, OS command injection, and WAF detection bypass.
CISA expanded the KEV catalog with eight flaws, but five of them have been flagged as exploited before.
The hackers targeted LayerZero’s DVN, compromising certain RPCs and DDoSing others to trigger failover to the poisoned infrastructure.
Tyler Buchanan admitted in court to hacking into various companies, defrauding them, and stealing cryptocurrency from multiple individuals.
The machine emulator has been abused in at least two different campaigns distributing ransomware and remote access tools.
The continued use of the half-century-old protocol exposes enterprises and end users to various types of attacks.
In-the-wild exploitation has been ongoing for a year, but no successful payload execution has been observed.
Threat actors are reusing Tycoon 2FA tools across other phishing kits following the platform’s disruption.
Kejia Wang and Zhenxing Wang compromised the identities of dozens of US persons to help land jobs at over 100 companies.
An indirect prompt injection could be chained with a sandbox bypass and Cursor’s remote tunnel feature for shell access to machines.
Authorities in 21 countries participated in a coordinated action against DDoS-for-hire services.
The startup is leveraging AI to prevent AI-powered attacks across applications, users, machines, and cloud workloads.
The flaw allows low-privileged users to upload files to a temporary directory to achieve remote code execution.
To optimize management of CVE volume, entries that do not meet specific criteria will not be automatically enriched.
The flaws can be exploited remotely to impersonate users or execute arbitrary commands on the underlying OS.
The automotive analysis and data company is working with external experts to investigate the attack.
The Israeli startup aims to secure AI agents at runtime, continuously monitoring their behavior to prevent unsafe actions.