-
A financially motivated threat actor tracked as BREEZE COMET has breached Brazilian financial, retail, and eCommerce organizations, using privileged access to payment platforms to execute hundreds of fraudulent transactions in tightly timed waves. The …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Critical HPE Fabric Composer Flaw Lets Unauthenticated Attackers Execute Commands as Privileged User

Hewlett Packard Enterprise (HPE) has released security updates addressing 52 vulnerabilities in HPE Networking Fabric Composer, including two critical flaws that could allow unauthenticated remote attackers to gain administrative control or execute com…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 15…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed vulnerability in the Hugging Face Transformers library could allow attacker-controlled Python files to be written to a victim’s system before the user approves the execution of remote code. This vulnerability is tracked as CVE-2026-80…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are using a layered fake IT-support campaign to obtain remote access, deploy a malicious MSI package and conceal hands-on-keyboard activity behind legitimate signed applications and AWS API Gateway infrastructure. The operation demonstrat…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise Windows devices. Victims span healthcare, manufacturing, gaming, technology, logistics, government…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OWASP has launched the Open Automated Security Initiative for Software (OASIS), a new community project aimed at accelerating the remediation of vulnerabilities in open-source software through AI-generated patches and human application-security validat…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated malware campaign has abused a trojanized installer for the legitimate Exodus cryptocurrency wallet to deploy a modular remote access trojan (RAT) capable of stealing browser credentials, session cookies, and extension data. The campaign…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic has launched Claude Fable 5.1 and Claude Mythos 5.1, two versions of the same advanced AI model designed to enhance capabilities in coding, knowledge work, scientific research, and cybersecurity operations. While Fable 5.1 is available to the…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Iran-linked threat actor Mirage Kitten is targeting software developers with fake recruitment assessments that hide two newly identified cross-platform remote access trojans: NodeRabbit and PollCat. The campaign uses recruiter impersonation on LinkedIn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶

