A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.
Hi, what are you looking for?
A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.
Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks.
Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products.
AI can help attackers generate malware, create malicious payloads, bypass simple security checks, and convert vague malicious intent into functional code.
A stack-based buffer overflow bug can be exploited for remote code execution on a vulnerable device.
The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers.
Exploiting a confused deputy weakness, the hackers simply asked the chatbot to link the account to a new email address.
Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud.
Dashlane’s security systems automatically locked accounts to protect them against the hacking attempts.
Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster.
The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations.
Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime.
Organizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation.
Dragos said customers will soon gain expanded asset visibility and integrated device intelligence, with automated remediation workflows and a unified platform experience to follow.
AI’s use in the military is part of the administration’s larger push to grow the capability it sees as a unique American advantage.
Proof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems.
Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure.
Moscow’s agents are building fake companies, recruiting middlemen and deploying cyber spies and hackers who gather information that could be used to attack key infrastructure.
The one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow.
Noteworthy stories that might have slipped under the radar: Trump Mobile exposes customer data, phishers target the 2026 FIFA World Cup, CISA responds to recent supply chain attacks.