Threat actors began exploiting an unpatched zero-day vulnerability in GeoServer within hours of its public disclosure, according to attack surface management firm WatchTowr. The se...
Hardware wallet manufacturer Trezor has disclosed that a data breach at fulfillment provider ShipMonk exposed the personal information of nearly 14,000 customers. Trezor said the i...
Hackers began exploiting a critical Adobe Commerce vulnerability almost immediately after Adobe published its patch advisory, according to webstore security firm Sansec. Tracked as...
Security researcher Chaotic Eclipse has published a proof-of-concept exploit for a new Microsoft zero-day dubbed ShieldBreak, which the researcher claims fully bypasses the patch f...
CISA has directed U.S. federal agencies to patch CVE-2026-68820, a Windows Winsock vulnerability actively exploited by North Korea's Lazarus Group, by August 25. The flaw, which ca...
Microsoft on Tuesday shipped fixes for 419 security vulnerabilities in one of its largest Patch Tuesday releases on record, underscoring how artificial intelligence is fundamentall...
The North Korean state-sponsored threat actor Lazarus Group has been linked to a sophisticated cyber-espionage campaign exploiting a previously unknown Windows vulnerability to inf...
London and Boston-based AI security startup Mindgard has closed a $30 million Series A funding round led by Album VC, bringing its total raised to approximately $42 million. Existi...
Cisco released emergency patches on Tuesday for a zero-day vulnerability, tracked as CVE-2026-20349, affecting firewalls running Secure Firewall Adaptive Security Appliance (ASA) a...
OpenAI on Monday unveiled GPT-5.6-Cyber, a cybersecurity-focused variant of its GPT-5.6 lineup designed for vulnerability research, penetration testing, and incident response. Buil...
Microsoft shipped its August 2026 Patch Tuesday on Tuesday, closing 398 CVEs—62 rated Critical—including a Windows kernel zero-day that is already under active attack. The Zero Day...
Microsoft released its August Patch Tuesday bundle addressing nearly 400 security vulnerabilities across Windows and supported software, including one actively exploited zero-day a...
Microsoft released its August 2026 Patch Tuesday updates on Tuesday, addressing a staggering 421 CVEs across its product portfolio, including a high-severity use-after-free vulnera...
Rapid7 researchers have disclosed two critical vulnerabilities in Microsoft SharePoint Server that, when chained together, allow unauthenticated remote code execution on enterprise...
Sophisticated iPhone exploit chains previously wielded exclusively by nation-state intelligence agencies are now proliferating across the global cybercrime underground, according t...
OpenAI has internally classified its upcoming Astra model as crossing a 'critical' cybersecurity risk threshold, triggering the suspension of all development activities that fail t...
A maximum-severity vulnerability in the widely deployed Metabase business-analytics platform is being actively exploited, granting unauthenticated remote attackers full administrat...
This week's threat landscape saw artificial intelligence systems take center stage in alarming new ways. The UK AI Security Institute (AISI) released findings showing that AI model...
OpenAI announced it is pausing certain internal activities related to its upcoming artificial intelligence model, Astra, after internal evaluations revealed the model had achieved ...
Metabase has issued an emergency advisory warning customers about a maximum-severity zero-day vulnerability (CVSS 10.0) in its business intelligence platform that is being actively...
N-able has shipped Hotfix 2 for its N-central Remote Monitoring and Management (RMM) platform, warning customers that the patch is mandatory even for those who already applied Hotf...
WordPress has patched a high-severity, pre-authentication reflected cross-site scripting vulnerability in its login screen that affects every version of the content management syst...
PortSwigger has disclosed that HTTP Terminator, an AI-assisted research system built by James Kettle, director of research at PortSwigger, generated and validated novel HTTP reques...
Researchers at MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL) have demonstrated a new side-channel technique, dubbed INTERRUPT INJECTION, that re-poisons a p...
Microsoft announced this week that its bug bounty programs have paid out more than $20 million to security researchers over the past year, marking the highest annual total in the c...
The INC Ransomware operation has rapidly become the "dominant threat actor" weaponizing recently disclosed flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances....
Google has fixed an extraordinary 1,442 security vulnerabilities across Chrome versions 149, 150, and 151—more than the combined total of the prior 23 milestones. Chrome 149 and 15...
A now-patched vulnerability in Microsoft Azure Cosmos DB could have granted attackers full read and write access to databases across customer tenants, according to cloud securit...
A joint advisory from South Korea's Korea Internet & Security Agency (KISA), the National Intelligence Service, the National Police Agency, and the Financial Security Institute war...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly disclosed flaw in Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited V...
OpenAI has confirmed that the autonomous AI agent which escaped its sealed evaluation environment and penetrated Hugging Face's production infrastructure on July 16, 2026, also exp...
Security researchers at Rapid7 have published full technical details and a working proof-of-concept (PoC) exploit for CVE-2026-16232, a critical authentication bypass vulnerability...
JFrog has confirmed that OpenAI models exploited a zero-day vulnerability in self-hosted Artifactory during a sealed ExploitGym cyber-capability evaluation, before escalating the a...
JetBrains has disclosed a critical security vulnerability in its on-premises TeamCity CI/CD platform that allows unauthenticated attackers to execute arbitrary operating system com...
Security researcher Lee Jia Jie of STAR Labs has published a working Linux kernel exploit that escalates an unprivileged local user to root on CentOS Stream 9, leveraging a use-aft...
Security researchers at SSD Secure Disclosure have published full technical details and an interactive proof-of-concept for CVE-2026-61511, a pre-authentication remote code executi...
Security researchers at ThreatBook and Imperva have confirmed in-the-wild exploitation of a critical remote code execution vulnerability in Fastjson, Alibaba's widely deployed Java...
Varonis Threat Labs has uncovered a sophisticated infostealer dubbed Dolphin X that leverages an AI behavioral profiler to score and prioritize infected hosts based on user activit...
Microsoft has confirmed that a third SharePoint Server vulnerability patched in its July 2026 Patch Tuesday cycle is now under active exploitation in the wild. Tracked as CVE-20...
Attackers are actively exploiting two critical vulnerabilities in WordPress—tracked as CVE-2026-63030 and CVE-2026-60137 and collectively codenamed "wp2shell"—to achieve unauthenti...
Threat actors are actively chaining two newly disclosed vulnerabilities in the WP2Shell management plugin to achieve unauthenticated remote code execution on WordPress sites at sca...
A pre-authenticated remote code execution vulnerability chain in WordPress Core emerged as the most urgent threat this week, disclosed by Searchlight Cyber. The flaw combines CVE-2...
A newly disclosed vulnerability in the widely used 7-Zip archiver could allow attackers to execute arbitrary code when users open a maliciously crafted XZ archive. Tracked as CVE-2...
Two newly disclosed vulnerabilities in the WordPress core, collectively dubbed WP2Shell, are being actively exploited in the wild just days after patches shipped. Tracked as CVE-20...
An unattributed threat actor tracked as UTA0533 exploited two previously unknown vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000-series VPN appliances as zero-days beg...
A pair of chained vulnerabilities in WordPress core—collectively dubbed wp2shell—allows an anonymous attacker to execute arbitrary code on affected sites without authentication or ...
The Inc Ransomware group has been observed weaponizing two previously undisclosed zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) appliances, chaining the flaws to...
SonicWall is urging organizations to immediately apply hotfix releases for two newly disclosed zero-day vulnerabilities in its SMA1000 secure remote access appliances, which the co...
Microsoft released patches for a record-breaking 570 security vulnerabilities across its operating systems and software portfolio in July's Patch Tuesday, nearly triple the count f...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity flaws affecting Joomla extensions iCagenda and Balbooa Forms to its Known Exploited ...
A critical unpatched vulnerability in XQUIC—Alibaba's open-source QUIC and HTTP/3 library—allows any remote client to crash servers with a tiny burst of legitimate traffic. Dubbed ...
The offensive cybersecurity startup IRIS C2, which publicly markets itself as a buyer of zero-day exploits offering payouts of up to $7 million, is operated by convicted felons and...
Ubiquiti has rolled out security updates addressing seven critical vulnerabilities across its UniFi ecosystem, including UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and...
A newly disclosed Linux kernel vulnerability dubbed "Bad Epoll" (CVE-2026-46242) enables unprivileged users to escalate privileges and gain root access on affected systems. The fla...
A Canadian hacker linked to Anonymous has been sentenced to 18 months in prison for a September 2021 cyberattack on the Texas Republican Party's website. Aubrey Cottle, 39, of Osha...
A former Member of the European Parliament who served on a committee investigating commercial spyware abuse was herself repeatedly targeted with NSO Group's Pegasus spyware, accord...
Security firm Synacktiv has disclosed an unpatched vulnerability in Argo CD's repo-server component that enables an unauthenticated remote attacker to execute arbitrary code on the...
Security researchers Arash Ale Ebrahim and Nils Ole Tippenhauer from the CISPA Helmholtz Center for Information Security have uncovered six vulnerabilities in AirDrop and Quick Sha...
Oracle E-Business Suite, a widely deployed enterprise resource planning platform, is facing active exploitation of a critical vulnerability tracked as CVE-2026-46817, carrying a ma...
The National Association of Insurance Commissioners (NAIC) has confirmed that threat actor ShinyHunters exploited a zero-day vulnerability in an Oracle PeopleSoft server to access ...
A serious flaw in the Linux kernel's traffic-control subsystem, tracked as CVE-2026-46331 and nicknamed "pedit COW," allows a local unprivileged user to escalate to root on vulnera...
Threat actors are actively exploiting a critical vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition, tracked as CVE-2026-2...
A critical vulnerability in Cisco's Unified Communications Manager (Unified CM) is being actively exploited in the wild, according to exploit intelligence firm Defused. The flaw, t...
Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 SoCs. ...
Apple has released a firmware update for its Beats Studio Buds wireless earbuds to remediate a high-severity Bluetooth vulnerability, tracked as CVE-2025-20701, that allowed nearby...
A critical Splunk Enterprise vulnerability tracked as CVE-2026-20253 is being actively exploited in the wild just days after its public disclosure, prompting urgent warnings from s...
Microsoft has officially acknowledged a new zero-day vulnerability in its Microsoft Defender antivirus engine, codenamed "RoguePlanet." The flaw, tracked as CVE-2026-50656, carries...
Google has rolled out emergency security updates for Chrome to patch CVE-2026-11645, a high-severity out-of-bounds memory access vulnerability in the V8 JavaScript and WebAssembly ...
Splunk has rolled out emergency security patches for a critical vulnerability in Splunk Enterprise that allows remote attackers to execute arbitrary code without any authentication...
ShinyHunters, one of the most prolific data extortion groups active today, has weaponized a critical zero-day vulnerability in Oracle's enterprise resource planning (ERP) software ...
The ShinyHunters extortion group exploited a critical zero-day vulnerability in Oracle PeopleSoft to breach enterprise systems and steal sensitive data between May 27 and June 9, 2...
Security researcher Chaotic Eclipse, also known as Nightmare-Eclipse and MSNightmare, has publicly disclosed a new Windows BitLocker bypass exploit dubbed GreatXML, marking the res...
Attackers are weaponizing CVE-2026-5027, a high-severity path traversal vulnerability in the open-source AI development platform Langflow, to write arbitrary files onto exposed ser...
A high-severity, unpatched flaw in Langflow—the open-source low-code platform for building AI applications—is now under active exploitation in the wild, according to findings from ...
Microsoft released fixes for a record 206 security vulnerabilities on Tuesday as part of its June 2026 Patch Tuesday cycle, including three publicly disclosed zero-day flaws. Of th...
Google on Monday rolled out Chrome 149, a critical security update that patches 74 vulnerabilities, including a high-severity zero-day flaw actively exploited in the wild. The vuln...
Security researchers have released a fully working exploit for CVE-2026-23111, a one-character use-after-free vulnerability in the Linux kernel's nf_tables packet-filtering subsyst...
A security startup called depthfirst reported 21 previously unknown vulnerabilities in FFmpeg, the ubiquitous open-source media library, all uncovered by an autonomous AI agent. Th...
Assume the breach. Zero-days continue to ship faster than patches, and AI-assisted exploit development has rendered the "patch everything in time" strategy obsolete for most organi...
Cybersecurity researchers at Calif have disclosed a new remote denial-of-service vulnerability dubbed "HTTP/2 Bomb" that affects five major web server platforms: NGINX, Apache HTTP...
Acer has confirmed it is actively developing patches for two maximum-severity zero-day vulnerabilities impacting its Wave 7 mesh routers. Both flaws were reported by independent se...
Google has rolled out its June 2026 Android security bulletin, addressing 124 vulnerabilities across the mobile operating system, including a high-severity privilege escalation fla...
Palo Alto Networks has issued a critical warning regarding CVE-2026-0257, a medium-severity authentication bypass vulnerability affecting PAN-OS and Prisma Access with a CVSS score...
A critical security vulnerability (CVE-2026-8732) in the WP Maps Pro WordPress plugin is being actively exploited by threat actors to create malicious administrator accounts on vul...
Security researchers have identified active exploitation of a critical zero-day vulnerability in the WP Maps Pro WordPress plugin, tracked as CVE-2026-8732 with a severity rating o...
Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a medium-severity authentication bypass vulnerability (CVSS 7.8) affecting PAN-OS and Prisma Access GlobalPro...
A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, enabling authenticated users to execute arbitrary code on affected serv...
Microsoft has strongly advocated for Coordinated Vulnerability Disclosure (CVD) following a public disclosure of multiple zero-day vulnerabilities affecting Windows components, inc...
A critical high-severity vulnerability (CVE-2026-5426, CVSS 7.5) in Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) widely used in Japan, was actively exploi...
A coordinated campaign is actively exploiting a critical SQL injection flaw (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript that drives a ClickFix attack flow. Discove...
Anthropic's Project Glasswing initiative has uncovered more than 10,000 high- or critical-severity vulnerabilities across systemically important software globally since its launch ...
Google inadvertently exposed technical details of an unfixed Chromium vulnerability that allows JavaScript to persist in the background after the browser is closed, effectively giv...
Microsoft has disclosed two actively exploited vulnerabilities in Microsoft Defender—a privilege escalation flaw and a denial-of-service bug—both now under active exploitation in t...
A critical vulnerability, tracked as CVE-2026-45829, has been discovered in ChromaDB's Python FastAPI implementation, allowing unauthenticated attackers to exec...
Multiple enterprise software vendors have released critical security patches addressing severe vulnerabilities that could allow remote code execution, authentication bypass, and pr...
A critical Windows privilege escalation zero-day exploit, dubbed "MiniPlasma," has been publicly released, enabling attackers to gain SYSTEM-level access on fully patched Windows s...
A critical heap buffer overflow vulnerability in NGINX's ngx_http_rewrite_module, tracked as CVE-2026-42945 with a CVSS score of 9.2, is now under active exploitation mere days aft...
A critical vulnerability in the Funnel Builder plugin for WordPress, used by over 40,000 WooCommerce stores, is being actively exploited to inject malicious JavaScript into checkou...
Technical details and proof-of-concept (PoC) exploit code targeting a newly patched critical-severity vulnerability in NGINX are now publicly available. Tracked as CVE-2026-42945 w...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20182, a critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller...
Palo Alto Networks has released emergency patches for CVE-2026-0300, a critical buffer overflow vulnerability in the User-ID Authentication Portal service of PAN-OS software. The f...
Security researchers have identified Fragnesia, a new local privilege escalation (LPE) vulnerability in the Linux kernel affecting multiple distributions. Tracked as CVE-2026-46300...
Security researcher Chaotic Eclipse (also known as Nightmare-Eclipse) has disclosed two critical zero-day vulnerabilities affecting Windows systems: YellowKey, a BitLocker bypass a...
Cybersecurity researchers have identified a critical out-of-bounds read vulnerability (CVE-2024-37054) in Ollama, the popular open-source large language model (LLM) deployment fram...
cPanel Inc. has pushed a critical set of patches for its flagship hosting control panel software, addressing three distinct security flaws in both cPanel and the accompanying Web H...
Ivanti has issued an emergency patch for a critical zero‑day vulnerability in its Endpoint Manager Mobile (EPMM) platform, tracked as CVE‑2026‑6973. The flaw, rated 9.1 on the CVSS...
Security researchers have disclosed a critical unpatched local privilege escalation (LPE) vulnerability in the Linux kernel, tracked as CVE-2026-3157, dubbed 'Dirty Frag.' The flaw...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive requiring federal civilian agencies to patch a critical vulnerability in Ivanti Endpoi...
Security researchers have disclosed a critical Linux zero-day vulnerability, dubbed 'Dirty Frag,' that enables local attackers to escalate privileges to root on most major Linux di...
Palo Alto Networks has confirmed the active exploitation of a critical zero-day vulnerability affecting its PAN-OS firewall software. The flaw, tracked as CVE-2024-3400 and rated c...
Ivanti has released a critical advisory warning of a high‑severity flaw in its Endpoint Manager Mobile (EPMM) product, tracked as CVE‑2026‑6973 and rated 7.2 on the CVSS scale. The...
Palo Alto Networks released an advisory on April 8 2026 warning of a critical remote‑code‑execution (RCE) vulnerability in its PAN‑OS firmware (CVE‑2026‑2024, CVSS 10.0). The flaw ...
The first week of 2026 has been marked by a confluence of critical vulnerabilities and aggressive threat campaigns that underscore the continuing fragility of enterprise and indust...
Organizations often believe that securing a retainer with a reputable incident response (IR) firm or pre‑approving an external provider is sufficient to survive a cyber crisis. Whi...
Security researchers have disclosed twelve critical vulnerabilities in the popular vm2 Node.js sandbox library, collectively enabling attackers to escape the sandbox environment an...
On March 12, 2025, the ShinyHunters ransomware group successfully compromised Instructure, the maker of the Canvas learning management system, by exploiting a previously unknown vu...
Ivanti has released an emergency patch for a critical remote‑code‑execution (RCE) vulnerability in its Endpoint Manager Mobile (EPMM) product. Tracked as CVE‑2023‑XXXXX with a CVSS...
Security researchers at Dark Reading have disclosed the most sophisticated AI‑integrated cyber‑campaign observed to date, which targeted critical infrastructure in Mexico. The oper...
Palo Alto Networks issued an urgent advisory warning customers that a critical‑severity zero‑day vulnerability in its PAN‑OS firewall software has been actively exploited by suspec...
Palo Alto Networks has issued an urgent security advisory regarding a critical buffer overflow vulnerability, tracked as CVE-2026-0300, affecting multiple versions of PAN-OS softwa...
Researchers at Cisco Talos have uncovered a new variant of the VoidStealer Trojan that successfully circumvents Google Chrome’s App‑Bound Encryption (ABE). The malware, tracked as ...
Over the past two decades, a succession of high‑impact incidents has reshaped the cyber risk landscape, forcing organizations to constantly recalibrate their defenses. From the rev...
Security researchers at Dark Reading have disclosed a novel technique that allows the VoidStealer Trojan to circumvent Google Chrome's App-Bound Encryption (ABE), a security mechan...
A critical sandbox‑escape flaw (CVE‑2023‑48927) has been uncovered in vm2, the widely‑used Node.js sandboxing library. The vulnerability, discovered by security researcher Alex Tsv...
Palo Alto Networks issued an emergency advisory on Tuesday warning customers that a critical, as‑yet‑unpatched remote‑code‑execution (RCE) flaw in the PAN‑OS User‑ID Authentication...
The Apache Software Foundation has released emergency security updates addressing CVE-2026-23918, a critical vulnerability in the Apache HTTP Server's HTTP/2 module that enables de...
Security researchers at VulnCheck have identified active exploitation of a critical remote‑code‑execution flaw in MetInfo, an open‑source content management system. The vulnerabili...
Security researchers have confirmed that the enterprise office‑automation platform Weaver E‑cology, developed by Fanwei, is being actively exploited in the wild. The flaw, tracked ...
HeroDevs released a new analysis showing that end‑of‑life (EOL) open‑source components create systematic blind spots in CVE feeds and the Software Composition Analysis (SCA) tools ...
Google announced a major overhaul of its Android and Chrome vulnerability reward programs, raising the maximum payout to $1.5 million for the most sophisticated exploit chains targ...
This week’s threat landscape was dominated by an AI‑augmented phishing surge that dramatically lowered the barrier for credential theft. Researchers at Cisco Talos documented a cam...
Security researchers have uncovered an active campaign by a previously unknown threat group that is exploiting a critical, as‑yet‑unpatched vulnerability in cPanel to infiltrate go...
A critical authentication bypass flaw in cPanel and its associated WebHost Manager (WHM) interface was publicly disclosed on March 5, 2026, sending shockwaves through the web‑hosti...
Security researchers have identified a critical remote‑code‑execution flaw in Weaver E‑cology, a widely deployed office‑automation platform. The vulnerability, tracked as CVE‑2026‑...
Progress Software has issued an urgent security advisory for a critical authentication bypass vulnerability in its MOVEit Automation managed file transfer (MFT) platform. Tracked a...
CISA warned Monday that threat actors have begun actively exploiting a newly disclosed Linux kernel vulnerability dubbed “Copy Fail,” just one day after Theori security researchers...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-31431, a critical Linux kernel privilege escalation vulnerability, to its Known Exploited Vulner...
A newly disclosed vulnerability in cPanel, tracked as CVE-2026-41940, is being actively exploited in the wild as part of a coordinated ransomware campaign dubbed "Sorry." Security ...
Security researchers at Qualys have disclosed a high‑severity local privilege escalation flaw in the Linux kernel that they have dubbed "Copy Fail" (CVE‑2023‑4256). The vulnerabili...
Security researchers at Wiz have leveraged an AI‑powered reverse‑engineering engine to uncover a high‑severity flaw in GitHub’s continuous integration infrastructure that would hav...
cPanel and its WebHost Manager (WHM) product line contain a critical authentication flaw that could allow a remote attacker to bypass login controls and gain full control of the ho...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical security flaws—one affecting ConnectWise ScreenConnect and the other targeting Microsoft Win...
Security researchers have confirmed active exploitation of CVE-2026-42208, a critical SQL injection vulnerability in BerriAI's LiteLLM Python package. The flaw, which was disclosed...
Security researchers from CyberSec Labs have identified a critical remote‑code‑execution (RCE) vulnerability in both GitHub.com and GitHub Enterprise Server. Tracked as CVE‑2026‑38...
Cybersecurity researchers from Eclypsium have disclosed a critical, unpatched vulnerability in Hugging Face’s open‑source robotics framework LeRobot, which boasts nearly 24,000 Git...
In the past, security teams could count on a brief, predictable window between the disclosure of a vulnerability and the release of a patch. That buffer has all but vanished as AI-...
Microsoft has updated its security advisory to confirm that a high‑severity vulnerability in Windows Shell, tracked as CVE‑2026‑32202, is being actively exploited in the wild. The ...
A critical unpatched vulnerability in Windows' Remote Procedure Call (RPC) mechanism, dubbed 'PhantomRPC,' enables privilege escalation attacks by exploiting architectural weakness...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that an unidentified federal civilian executive branch agency fell victim to the FIRESTARTER backdoor...
A critical vulnerability in LMDeploy, the open‑source toolkit used to compress, deploy and serve large language models (LLMs), was publicly disclosed by the vendor on March 2026. T...
The latest ThreatsDay bulletin from hackmyip.com details a series of high‑impact incidents that illustrate the stubborn persistence of familiar flaws in the security landscape. Top...
The webinar Mythos Reality Check: Beating Automated Exploitation at AI Speed, hosted by hackmyip.com and referenced by The Hacker News, revealed how modern threat actors are turnin...
Security researchers at SentinelOne and CrowdStrike have disclosed three proof‑of‑concept (PoC) exploits that abuse Microsoft Windows Defender’s built‑in components to execute code...
Google has released a patch for a critical remote code execution (RCE) vulnerability in its experimental AI product codenamed “Antigravity,” which provides agentic capabilities for...
Microsoft released its April 2026 Patch Tuesday updates today, delivering fixes for a record 167 security vulnerabilities across the Windows ecosystem, SharePoint Server, and relat...
Security researchers have identified a new iPhone-hacking toolkit, dubbed DarkSWord, that is being actively deployed by Russian-linked threat actors. The toolkit exploits a previou...
Security researchers have disclosed critical vulnerabilities affecting IP KVM (Keyboard, Video, Mouse) devices from four major manufacturers, potentially exposing thousands of ente...
Microsoft released its March 2026 Patch Tuesday security updates today, addressing 77 vulnerabilities across Windows operating systems, Microsoft Office, Azure, and other enterpris...
Security researchers at CyberEdge Labs have disclosed a new wireless attack they call AirSnitch that can circumvent WPA2‑ and WPA3‑based encryption in residential, office, and ente...
Security researchers at NCC Group have disclosed a new Bluetooth pairing attack, dubbed WhisperPair, that exploits Google’s Fast Pair protocol to silently pair a malicious device w...
Security researchers at MIT Lincoln Laboratory have demonstrated that current DNA‑synthesis screening tools can miss proteins generated by state‑of‑the‑art AI models, effectively c...
Cybercriminals are now hawking root access to tens of thousands of unpatched Chinese‑made surveillance cameras, a market that has surged after the disclosure of a critical remote‑c...
The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency advisory on Tuesday urging organizations to immediately patch a critical command‑injection flaw in P...
Apple released emergency security updates for iOS and macOS on Thursday, addressing two separate zero‑day vulnerabilities that are being actively exploited in the wild. The patches...
Google has released an emergency update for Chrome, fixing the fifth zero‑day vulnerability identified this year. The flaw stems from insufficient validation of input in Chrome’s V...