Hackers rely on evolved vishing and login harvesting to compromise SSO credentials for unauthorized MFA enrollment.
Hi, what are you looking for?
Hackers rely on evolved vishing and login harvesting to compromise SSO credentials for unauthorized MFA enrollment.
A hacker published malicious versions of four established VS Code extensions to distribute a GlassWorm malware loader.
Of 3,100 unprotected MongoDB instances, half remain compromised, most of them by a single threat actor.
The next major Windows Server and Windows releases will have the deprecated authentication protocol disabled by default.
Hackers compromised a MicroWorld Technologies update server and fed a malicious file to eScan customers.
Among them, 23,000 hosts were persistently responsible for the majority of activity observed over 293 days of scanning.
Android users were lured to applications that served a malicious payload hosted in a Hugging Face repository.
The critical-severity vulnerabilities could allow unauthenticated attackers to execute arbitrary code remotely.
An LLMjacking operation has been targeting exposed LLMs and MCPs at scale, for commercial monetization.
The two bugs impacted n8n’s sandbox mechanism and could be exploited via weaknesses in the AST sanitization logic.
The four critical flaws could be exploited without authentication for remote code execution or authentication bypass.
One of the largest residential proxy networks, IPIDEA enrolled devices through SDKs for mobile and desktop.
The investment will allow Mesh to advance its autonomous, agentic capabilities, and scale sales and customer support efforts.
New Strict Account Settings allow users to block attachments and media and silence calls from unknown people.
Russian and Chinese state-sponsored threat actors have been exploiting CVE-2025-8088 since July 2025.
Tracked as CVE-2026-24858, the bug allows attackers to log into devices registered to other FortiCloud accounts.
The startup will use the investment to fuel global expansion of its agentless platform, including in Latin America.
The protections against NPM supply chain attacks could be bypassed, leading to arbitrary code execution.
Marketed as ChatGPT enhancement and productivity tools, the extensions allow the threat actor to access the victim's ChatGPT data.
The flaws allow threat actors to obtain root privileges or bypass authentication via Telnet and gain shell access as root.