Exploits swirling for remote code execution vulnerability (CVE-2025-24813) in open-source Apache Tomcat web server.
Hi, what are you looking for?
Exploits swirling for remote code execution vulnerability (CVE-2025-24813) in open-source Apache Tomcat web server.
Meta’s Facebook security team warns of live exploitation of a zero-day vulnerability in the open-source FreeType library.
China-nexus cyberespionage group caught planting custom backdoors on end-of-life Juniper Networks Junos OS routers.
Apple warns that the WebKIt bug "may have been exploited in an extremely sophisticated attack against specific targeted individuals.”
Redmond ships major security updates with warnings that a half-dozen Windows vulnerabilities have already been exploited in the wild.
Adobe documents 35 security flaws in a wide range of products, including code-execution issues in the Acrobat and Reader applications.
Two men linked to Garantex are accused of facilitating multi-billion dollar money laundering and sanctions violations.
The $1.4 billion ByBit cryptocurrency heist combined social engineering, stolen AWS session tokens, MFA bypasses and a rigged JavaScript file.
i-Soon employees charged with conducting extensive hacking campaigns on behalf of Beijing’s security services.
SpecterOps has raised an unusually large $75 million Series B funding round to accelerate the growth of its BloodHound Enterprise platform.
Silk Typhoon APT caught using IT supply chain entry points to conduct reconnaissance, siphon data, and move laterally on victim networks.
Knostic provides a “need-to-know” filter on the answers generated by enterprise large language models (LLM) tools.
The CISA public clarification follows news the Trump administration is temporarily pausing offensive cyber operations against Moscow.
Amnesty International publishes technical details on zero-day vulnerabilities exploited by Cellebrite’s mobile forensic tools to spy on a Serbian student activist.
Dreadnode is building “offensive machine learning” tools to safely simulate how AI models might be exploited in the wild.
Seattle startup building technology to mitigate lateral movement and block “living off the land” techniques wins interest from investors.
Apple says it can no longer offer end-to-end encrypted cloud backups in the UK and insists it will never build a backdoor or master...
Cisco Talos observed Chinese hackers pivoting from a compromised device operated by one telecom to target a device in another telecom.
China-linked cyberespionage toolkits are popping up in ransomware attacks, forcing defenders to rethink how they combat state-backed hackers.
Mandiant warns that multiple Russian APTs are abusing a nifty Signal Messenger feature to surreptitiously spy on encrypted conversations.