Splunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies.
Hi, what are you looking for?
Splunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies.
Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root.
Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code.
The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control.
The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges.
The browser updates address multiple memory safety bugs that could potentially lead to remote code execution.
The flaws allow attackers to execute arbitrary PHP code and gain root privileges on shared hosting servers.
The company is enhancing third-party risk management (TPRM) through autonomous AI agents.
The hack-and-leak group FulcrumSec claims to have stolen 1.3TB of data from the pharmaceutical giant.
NSPM-12 establishes a clear structure for NSS cybersecurity governance and accountability and reestablishes CNSS.
Arch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR.
Over two dozen organizations built a shared platform to triage vulnerabilities, fix them, and secure the software before patches arrive.
The startup has built a security-first identity platform to protect humans, machines, and AI agents.
Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang.
The extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information.
The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses.
By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed.
The hackers published 5GB of data, including customer personal information and credentials for the RTKBase platform.
The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.
The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs.