Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx.
Hi, what are you looking for?
Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx.
Now in its third year, the AI Risk Summit is the leading conference that brings together CISOs, security leaders, AI researchers, developers, policymakers, and enterprise risk professionals.
Using an AI model called BinNet, RevEng hunts vulnerabilities and backdoors in released software binaries.
Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network.
The new funding, led by BDC Capital’s StrongNorth Fund, will accelerate Lastwall’s North American expansion.
As AI accelerates phishing, session hijacking, and credential abuse, security teams are racing to close the gap between attacker speed and defensive response.
Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipelines, and deploying malicious code.
Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware.
The attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors.
The FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms.
Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges.
The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally.
Marlin AI automatically analyzes SaaS misconfigurations, investigates related activity across enterprise environments, and recommends remediation steps — while stopping short of fully autonomous corrective action.
Nimbus Manticore has continued its operations during and after the US military campaign against Iran.
The allegedly stolen information leaked by ShinyHunters contains email addresses, names, addresses, and dates of birth.
Notable integrations include CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Fortinet, and Wiz.