Attackers are exploiting two AhsayCBS flaws to deploy web shells and XMRig miners, and Huntress says version 10.3.4 remains ...
U.S. authorities seized seven domains used by China-linked Flax Typhoon to scan networks and support intrusions into critical ...
Three teams demonstrated remote exploits against fully patched Pixel 10 phones at Pwn2Own Ireland, earning $562,500 in total.
Citrix patched CVE-2026-107406, a critical NetScaler memory overflow that could allow RCE or DoS in deployments configured ...
A public exploit for AnyDesk Linux 8.0.2 demonstrates pre-auth root command execution over direct TCP connections on port 7070.
Four more U.S. states sued TP-Link over allegedly misleading claims about router security and China ties, as 21 attorneys general contacted the FCC.
Anthropic's opt-in OSS Scanner offers free, periodic AI vulnerability scans for open-source projects, with no human review required for reports ...
CISA added five Flax Typhoon-exploited flaws to KEV, requiring federal agencies to patch affected software or stop using it by October 11, 2026.
SailPoint says 54% of organizations have no formal agent identity security program, versus 23% at the same maturity level for human identities.
JPCERT/CC links Japan's recent data leaks to mobile API abuse and known software flaws, including an exploited Metabase SQL ...
ThreatsDay: Malicious VS Code themes, npm supply-chain attacks, AI phishing, ransomware betrayal, exposed hacker tools, and ...
A GoBalance signing flaw lets attackers recover Tor-format .onion private keys from public descriptors and hijack affected site addresses.