-
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized Terraform lock files in fake job-interview repositories to infect DevOps engineers with macOS backdoors….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote code execution, sensitive-data exposure, and account compromise across major technology and enterpris…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds h…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Exim maintainers have released version 4.100.1 to address four security vulnerabilities affecting the widely used mail transfer agent. This update resolves issues that could potentially enable SMTP smuggling and heap-memory corruption under certain con…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have revealed a zero-click attack technique known as BragJack, which could enable a malicious browser extension to hijack built-in AI assistants in popular browsers like Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credentia…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors rapidly exploited a critical authentication bypass in cPanel and WHM to compromise internet-facing hosting servers, with Japanese telemetry data linking the campaign to a sharp rise in Mirai-like scanning and attack traffic targeting Teln…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently disclosed WordPress vulnerability, known as Click2Shell, could let attackers execute remote PHP code on vulnerable sites after convincing a logged-in administrator to click a specially crafted link. WordPress version 7.1.1, released on Septe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has confirmed that its Gemini artificial intelligence model accidentally accessed protected systems belonging to three real companies during a cybersecurity evaluation. The incident stemmed from a configuration error that exposed the AI agent to…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


