Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers...
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers,...
Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy
Chinese open-weight model GLM 5.2 happily obliged
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on...
WordPress security advisory (AV26-723)
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed...
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent...
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons...
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood...
Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
HPE security advisory (AV26-722)
GitHub security advisory (AV26-720)
Zimbra security advisory (AV26-721)
[Control systems] CISA ICS security advisories (AV26-718)
Red Hat security advisory (AV26-719)
Bulletin de sécurité GitHub (AV26-720)
Dell security advisory (AV26-716)
Ubuntu security advisory (AV26-717)
IBM security advisory (AV26-715)
CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-57309 to CVE-2026-57311) found in Windu CMS software.
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and...
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet....
Apple and Google have long dominated the smartphone market, combining for roughly 5 billion active Android phones and iPhones worldwide, according to market research firm Omdia. And as AI...
Views of China have improved in recent years while opinions of the U.S. have worsened, to the point where China is now seen more positively than the U.S. in most of 36 countries surveyed....
Kenya’s official presidential website, president.go.ke, is back online after hackers defaced its homepage and demanded a ransom of five Bitcoin, worth approximately KSh41.3 million (about...
On July 16, 2026, Hugging Face, the world’s largest AI model repository, publicly disclosed a breach of its production infrastructure. The intrusion was executed entirely by an autonomous AI...
Somewhere, a hard drive is filling up with secrets no one can read yet, and its owner is waiting for the machine that opens them all at once. On March 30, 2026, that wait got shorter. Two...
The automotive industry’s increasing use of over-the-air technology to update vehicle systems makes it more susceptible to cyberattacks, analysts say, urging more intervention in the sector. OTA...
When trusted tools become part of the attack chain, the old protection techniques fall short. Here are three that work.
When DeepSeek’s R1 debuted in early 2025, almost $600 billion was wiped out from Nvidia Corp.’s market value in a single day on fears that artificial intelligence would require less computing...
A recent examination of hundreds of mobile apps marketed toward US military personnel found more than one in eight contained software built by companies in China, Russia, or other foreign nations,...
Transform SOC data chaos into autonomous intelligence with modern AI pipelines and agentic AI to empower human analysts.
Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and MSNightmare) released his ninth unpatched Windows vulnerability called LegacyHive. This latest bug drop is a Local...
A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral. The New Jersey plates that were allegedly stolen from the LA dealer...
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it...
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal...
27 seconds. That’s the fastest time on record for an attacker to break into an endpoint and start moving laterally through a network. The average across all attacks in 2025 was 29 minutes, a 65%...
A new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports.
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple...
A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries.
A vulnerability chain has been discovered in WordPress Core that could allow for remote code execution. WordPress is an open-source content management system (CMS) used to design, build, and...
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was...
Master modern cyber threat hunting by embracing real-time threat intelligence. Discover the elite tools, steps, and frameworks to expose hidden adversaries.