The attackers had access to a senior executive’s email account for 150 days and exfiltrated data for months.
Hi, what are you looking for?
The attackers had access to a senior executive’s email account for 150 days and exfiltrated data for months.
The affected individuals’ personal information was stolen from a legacy server managed by a third party.
An improper authentication bug allows attackers to escalate their privileges and escape containers.
The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold.
Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.
The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release.
As AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control.
A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.
Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks.
Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products.
AI can help attackers generate malware, create malicious payloads, bypass simple security checks, and convert vague malicious intent into functional code.
A stack-based buffer overflow bug can be exploited for remote code execution on a vulnerable device.
The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers.
Exploiting a confused deputy weakness, the hackers simply asked the chatbot to link the account to a new email address.
Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud.
Dashlane’s security systems automatically locked accounts to protect them against the hacking attempts.
Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster.
The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations.
Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime.
Organizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation.