-
Dell has recently disclosed two critical vulnerabilities in PowerProtect Data Domain appliances that could allow unauthenticated remote attackers to gain complete control of affected systems. These vulnerabilities are tracked as CVE-2026-53483 and CVE-…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
11 malicious NuGet packages masquerading as game cheats, automation bots, and management “panels” that deploy a Windows payload called pepesoft.exe. The packages were published as .NET command-line tools, enabling users to install them through the dotn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A threat campaign targeting Indian government job seekers is using a recruitment notice for Senior Field Officer positions in the Cabinet Secretariat as a lure to deploy a custom remote access Trojan, SheetAgent RAT. The campaign begins with a ZIP arch…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Apple-focused scam operations are increasingly using FaceTime as a high-trust social-engineering channel to steal credentials and, in higher-risk cases, prepare victims for device compromise. Apple said threat actors may approach targets via phone call…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has addressed multiple information-disclosure vulnerabilities in the Windows Remote Desktop Protocol (RDP). This widely used service enables remote administration and access to Windows systems. The five flaws could permit attackers to retriev…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SonicWall has issued a security advisory regarding two vulnerabilities affecting the SMA1000 Series appliances. Among these, a critical server-side request forgery (SSRF) flaw has been identified, which carries a maximum CVSS score of 10.0. The company…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AI-enabled phishing-as-a-service operations are driving a sharp increase in identity attacks in 202620262026, with threat actors increasingly abusing OAuth device authorization flows and Microsoft Entra ID device enrollment to obtain durable access to …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google Chrome version 150 addresses vulnerabilities in several core browser components, including Ozone, Skia, V8, GPU, Media, UI, Navigation, libyuv, and Linux Toolkit Theming. Among the updates, two critical vulnerabilities, designated as CVE-2026-15…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Two vulnerabilities in Anthropic’s Claude for Chrome extension could allow a malicious browser extension to trigger AI-driven actions affecting a victim’s Gmail, Google Docs, and Google Calendar data. These issues are still reproducible in Claude for C…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A suspected China-linked threat actor has integrated Anthropic’s Claude Code and DeepSeek-v4-pro into an active intrusion campaign targeting government entities, Taiwanese industry, and financial-services organizations. TencShell was first documented b…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


