Red Hat disclosed an Important oc-mirror flaw that could bypass PGP verification and inject malicious images into disconnected OpenShift environments.
BambooToken Linux backdoor uses MQTT for remote control, allowing attackers to run commands, collect host data, and transfer files.
A zero-day vulnerability in Meta’s Muse AI agent for macOS could allow malware already running under a user account to hijack ...
Aikido Security introduced Altar-1, an open-weight AI model built to run defensive cybersecurity tasks entirely.
A hidden prompt in a cloud decoy can stop AI agents during simulated attacks, working against both original and “abliterated” Qwen3.8-27B models.
GHAPPIER supply-chain attack compromised 22 accounts, infecting 65 GitHub repositories and 73 files with a malicious npm loader.
Hackers used fake websites and Chrome/Windows zero-days to target Asian governments with malware in a targeted espionage campaign.
D-Link is investigating a critical flaw in the DIR-822A router that allows unauthenticated remote compromise without user interaction.
Hackers target Windows domain controllers to steal Active Directory credentials, escalate privileges, and spread across ...
A newly detailed Windows privilege escalation flaw tracked as CVE-2026-66804 allowed a standard, low-privileged user to plant a malicious DLL and execute arbitrary code with full NT AUTHORITYSYSTEM ...
Chinese-speaking hackers exploited WordPress flaws to breach 49 organizations, steal credentials, plant webshells, etc..
Vidar stealer evolves its code to evade detection while stealing passwords, cookies, wallet data, and system details from victims.