Isolated-vm's ExternalCopy type confusion lets sandboxed code corrupt host memory and potentially reach host RCE; fixes are ...
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have ...
Chrome security update 151.0.7922.169/.170 patches 15 vulnerabilities, including two Critical sandbox-escape buffer overflows ...
Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach.
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect ...
A legitimate-looking link or valid digital signature can offer false reassurance. Here’s why familiar download safety checks ...
Kaspersky researchers found 92,000 malicious attacks disguised as AI services in 2026, with fake ChatGPT, Claude and Gemini ...
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without victims clicking a link.
With 3.5 billion active users to protect, Google is relying on Gemini to find Chrome security bugs fast - and before attackers do.
A phishing campaign targeting cybersecurity conference attendees has been using Google Docs and other familiar online services to deliver malware, including a Windows payload that can install its own ...
A critical vulnerability in the Node.js sandboxing library, isolated-vm, has exposed a serious risk to AI agents, automation ...