-
Hackers are increasingly exploiting vulnerabilities at an unprecedented speed, with nearly one in four flaws being abused before or on the same day they are publicly disclosed, according to VulnCheck’s State of Exploitation report for the first half of…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Home Assistant’s FFmpeg integration recently came under scrutiny after researchers demonstrated that unsafe argument handling in the Wyoming Assist satellite feature could be exploited to steal Supervisor tokens and ultimately execute commands as root …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom post‑exploitation toolchain, and, in multiple cases rapidly pivot to Chaos ransomware deployment across North Amer…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Work Panel is a turnkey vishing and phishing platform that industrializes enterprise account takeovers and MFA theft by packaging infrastructure automation, role-based operations, and real-time credential harvesting into a single criminal SaaS console….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Copybara is being weaponized in a new N26-themed fraud campaign in Italy that chains vishing, a real‑time phishing control kit, and a multi‑stage Android dropper to gain full remote control of victims’ phones via abused Accessibility services. The oper…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has released stable Chrome version 151 updates for Windows, macOS, and Linux, addressing 370 security vulnerabilities. This update includes fixes for seven critical-severity flaws that affect core components of the browser. The new versions are …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
North Korea–linked operators have quietly turned popular npm packages into a high‑volume access vector for developer and build environments, chaining multiple compromises of axios, debug, chalk, and typo‑crypto into a coordinated software supply‑chain …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GitLab has released security updates for both the Community Edition (CE) and Enterprise Edition (EE), addressing 13 vulnerabilities that could allow unauthorized data exposure, tampering with CI/CD pipelines, bypassing protected branches, and denial-of…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Node.js Project has released security updates for the active Node.js versions 22.x, 24.x, and 26.x, addressing 11 vulnerabilities. These vulnerabilities range from high-severity issues, such as HTTP/2 memory corruption and permission-bypass flaws, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent JavaScript backdoor, OWAReaper, that can survive credential rotation, browser restarts, and full hos…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


