Turla has been using the backdoor against government and military organizations in Ukraine for espionage.
Hi, what are you looking for?
Turla has been using the backdoor against government and military organizations in Ukraine for espionage.
The startup’s platform functions as a secure control layer, aiming to secure AI tools across enterprises.
The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects.
The latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities.
The guidance aims to establish product cybersecurity requirements for IoT devices integrated into federal agencies’ networks.
More than half of the bugs are use-after-free defects, which can potentially lead to remote code execution.
The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands.
Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.
The security defects allow unauthenticated users to take control of the open source software supply chain.
Over a dozen Klue customers have confirmed that hackers stole data from their Salesforce instances.
Attackers could abuse Dify's multi-tenant cloud service to read private chats, preview other tenants' documents, and reach internal APIs.
Attackers can send crafted media files to execute code in any application that uses FFmpeg’s libavcodec library.
OpenAI has expanded its Daybreak cybersecurity initiative with a new suite of tools and partnerships.
Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026.
Hackers stole customers’ names, addresses, email addresses, phone numbers, and account information.
Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data.
A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.
A database of over 86,000 confirmed working credentials was created during the credential-harvesting campaign.
HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers.
CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution.