-
Two alleged leading members of the Scattered Spider cybercrime collective have been sentenced to five years and six months in prison each for their involvement in the 2024 cyberattack on Transport for London (TfL). The National Crime Agency (NCA) descr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed vulnerability in 7-Zip could allow attackers to execute arbitrary code by tricking users into opening a specially crafted XZ-compressed file. Tracked as CVE-2026-14266 and identified by Trend Micro’s Zero Day Initiative as ZDI-26-444 …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Linux creator and top-level kernel maintainer Linus Torvalds has made it clear that the Linux kernel project will not adopt an anti-AI stance. He believes that large language models and related tools should be assessed based on their technical value ra…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A surge in ACR Stealer activity from late April through mid-June 2026, with operators combining ClickFix social engineering, WebDAV-hosted payloads, PowerShell obfuscation, and steganography to compromise enterprise users. The malware operations rely o…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload ins…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed zero-day vulnerability in AnyDesk has the potential to allow a local attacker to trigger a denial-of-service condition by exploiting the remote-access software’s “Send Support Information” feature. The advisory, tracked as ZDI-26-401 …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Millions of internet-connected Shark robot vacuums may be vulnerable to a critical remote code execution (RCE) flaw that could allow attackers to control devices remotely, access onboard cameras, retrieve home maps, and potentially steal stored Wi-Fi c…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are actively exploiting two zero-day vulnerabilities in the SonicWall SMA 1000 Series remote access appliances. They are chaining a critical server-side request forgery flaw with a local code injection bug to execute commands with root privileg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly proposed framework argues that AI penetration testing must move beyond conventional infrastructure compromise and assess whether an adversary can make an AI-enabled system act against its intended operational purpose. Traditional penetration te…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Next.js maintainers have announced a scheduled security release for July to address nine vulnerabilities, four rated high severity and five rated medium severity. The patches are expected to be released on July 20, 2022, and will include updated versio…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


