Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
Isolated-vm's ExternalCopy type confusion lets sandboxed code corrupt host memory and potentially reach host RCE; fixes are ...
Duolingo co-founder Severin Hacker steps down as CTO to focus on hands-on technical work while remaining on the board.
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. Although the threat actor has targeted government ...
Russian state hackers are using a maximum-severity vulnerability in Microsoft’s Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from ...
SilkParasite targets Central Asian governments with seven RATs, five newly documented, using DLL sideloading and likely ...
A malicious change was made to the legitimate QuickFox VPN installer, allowing it to secretly download a backdoor onto Windows PCs, according to Fortinet.
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal ...
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without victims clicking a link.
BdThemes supply chain attack poisoned JSON API exploiting XSS vulnerability to create rogue WordPress admin accounts and install webshells.
Cloudflare has introduced Kitesurf, a cloud-hosted browser designed for AI agents instead of people. The company says the browser uses less computing power than Chromium for common automation tasks, ...
China-linked Jewelbug used shared infrastructure to conduct government espionage and cryptocurrency fraud, logging more than ...