Attackers are exploiting an Atlassian Data Center flaw that enables unauthenticated access to specific webroot files.
CERT-UA found 100+ compromised sites using ClickFix lures to distribute LunexStealer to Windows search visitors.
SonicWall fixed four SMA1000 flaws, including a 10.0-rated SSRF reachable before authentication; it says none are known to be ...
Eight malicious npm packages downloaded 40,767 times deliver Overlord RAT, a Node.js stealer, and a downloader to Windows ...
FBI and USSS warn FortiBleed remains active, using stolen credentials and traffic sniffing to harvest Fortinet authentication data.
Canto Incognito has infected over 3,400 servers, using exposed AI and LLM infrastructure for crypto mining and botnet growth.
Anthropic expands reduced-safeguard AI access for vetted cyber teams after Project Glasswing verified at least 129,000 ...
Read the latest updates about Phishing on The Hacker News cybersecurity and information technology publication.
LMCache CVE-2026-105192 lets unauthenticated attackers run code when the multiprocess server is bound to a routable address; no fix exists.
Google temporarily stops OSS VRP product vulnerability reports after a surge in automated submissions, most of which it says ...
Picus says agentic pentesting proves live attack paths but leaves timing and coverage gaps that require complementary validation methods.
A human-operated phishing platform impersonates AI ad tools to capture credentials and MFA codes through ...