Threat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution.
Hi, what are you looking for?
Threat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution.
The company notified customers to manually shut down their servers while it is investigating a credible threat.
Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members.
The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages.
The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command.
A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware.
Hackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs.
Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access.
Hackers accessed the institution’s internal network and deleted two drives containing employee, student, and university data.
The security refresh resolves 13 use-after-free bugs, including two critical-severity flaws found by Google.
The Spanish startup has closed an extended pre-seed funding round two months after launching its digital identity protection platform.
Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface.
The professional services giant says it contained the incident, remediated its source, and experienced no operational or service delivery impact.
Cisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors.
The "Rogue Agent" vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same...
Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies...
Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication.
The alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data.
Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets.
Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10.