The botnet’s propagation is fueled by the AI-generated server deployments that use weak credentials, and legacy web stacks.
Hi, what are you looking for?
The botnet’s propagation is fueled by the AI-generated server deployments that use weak credentials, and legacy web stacks.
SAP has released 17 security notes, including four that address critical SQL injection, RCE, and code injection vulnerabilities.
The 44-year-old individual planted remote access malware on a logistics firm’s systems, with help from employees.
Hackers stole complete customer information, including contact details, national identity numbers, and payment details.
The social media platform confirmed that the issue allowed third parties to send password reset emails to Instagram users.
APT28 was seen impersonating popular webmail and VPN services, including Microsoft OWA, Google, and Sophos VPN portals.
Threat actors are hunting for misconfigured proxy servers to gain access to APIs for various LLMs.
The company will use the investment to accelerate platform adoption and expansion into the federal market.
The North Korean state-sponsored espionage group Kimsuky has targeted government organizations, think tanks, and academic institutions.
The Emergency Directives were retired because they achieved objectives or targeted vulnerabilities included in the KEV catalog.
Radware bypassed ChatGPT’s protections to exfiltrate user data and implant a persistent logic into the agent’s long-term memory.
Fresh attacks targeted three VMware ESXi vulnerabilities that were disclosed in March 2025 as zero-days.
The company will use the funds to enhance its AI-based narrative intelligence technology platform and accelerate go-to-market efforts.
The bug can allow attackers to read arbitrary files from the system, potentially exposing configurations and credentials.
Tracked as CVE-2026-21858 (CVSS score 10), the bug enables remote code execution without authentication.
The maximum-severity code injection flaw can be exploited without authentication for remote code execution.
Impersonating a legitimate extension from AITOPIA, the two malicious extensions were also exfiltrating users’ browser activity.
An error in the firmware-upload handler leads to devices starting an unauthenticated root-level Telnet service.
The critical-severity vulnerability allows unauthenticated, remote attackers to execute arbitrary shell commands.
Threat actors spoof legitimate domains to make their phishing emails appear to have been sent internally.