-
Security researchers Tom Stacey from PortSwigger and Tobia Righi from TurtleSec have introduced a new category of HTTP request smuggling attacks known as “CRLF-Powered Desync Attacks.” This method exploits a frequently overlooked HTTP heade…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have demonstrated a “Zombie Card” attack that can reactivate certain expired Visa contactless cards, allowing them to be used for NFC payments. This attack exploits a vulnerability in Visa’s EMV Kernel 3 regarding the handling of c…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has temporarily slowed the development of its latest frontier AI models after initial testing suggested that its upcoming Astra system may meet the company’s “Critical” cybersecurity capability threshold. This decision follows a rece…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency ap…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cisco has issued security updates for a high-severity vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to access sensitive configuration files on affected systems. This vulnerability is tracked as CVE-2026-20320 and i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact infection chain that begins with a victim manually executing a malicious PowerShell command. In la…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Multicluster Engine for Kubernetes. This flaw has a CVSS v3.1 score of 9.3. It could allow an unaut…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code execution (RCE) flaw in the Splunk MCP Server app. The vulnerabilities encompass deserialization, ac…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticate…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Researchers have revealed a pre-authentication remote code execution (RCE) vulnerability chain in CyberPanel that could allow an internet-based attacker to execute commands on vulnerable servers without any credentials. This attack combines exposed AI …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


