WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under ...
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without ...
A macOS ClickFix campaign uses more than 250 domains and server-side fingerprinting to hide AMOS lures from crawlers and ...
A leaked n8n API key is only the start. GitGuardian's research traces the full chain, from exposed tokens and weak keys to ...
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
Helical Insight, the open source Business Intelligence (BI) and Embedded Analytics platform developed by Helical IT Solutions, today announced a major enhancement to its free Community Edition, making ...
Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks ...
Convex is not the only application backend on the market. According to the company, one of its platform’s main ...
Google has released another update to the Chrome browser; 12 of the 41 vulnerabilities fixed were found by bug bounty hunters ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could ...
Microsoft 365 phishing campaign disclosed by Arctic Wolf Labs abuses Google Meet and Amazon S3 to bypass enterprise email ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results