The FBI arrested another suspected ShinyHunters co-conspirator whom news reports link to the breach of its jobs portal.
P7 DarkSword adds on-device keychain and crypto wallet data theft to the iOS exploit kit, alongside two-way C2 communication.
Attackers are exploiting two AhsayCBS flaws to deploy web shells and XMRig miners, and Huntress says version 10.3.4 remains ...
U.S. authorities seized seven domains used by China-linked Flax Typhoon to scan networks and support intrusions into critical ...
Three teams demonstrated remote exploits against fully patched Pixel 10 phones at Pwn2Own Ireland, earning $562,500 in total.
Citrix patched CVE-2026-107406, a critical NetScaler memory overflow that could allow RCE or DoS in deployments configured ...
Anthropic's opt-in OSS Scanner offers free, periodic AI vulnerability scans for open-source projects, with no human review required for reports ...
CISA added five Flax Typhoon-exploited flaws to KEV, requiring federal agencies to patch affected software or stop using it by October 11, 2026.
A public exploit for AnyDesk Linux 8.0.2 demonstrates pre-auth root command execution over direct TCP connections on port 7070.
SailPoint says 54% of organizations have no formal agent identity security program, versus 23% at the same maturity level for human identities.
A GoBalance signing flaw lets attackers recover Tor-format .onion private keys from public descriptors and hijack affected site addresses.
Four more U.S. states sued TP-Link over allegedly misleading claims about router security and China ties, as 21 attorneys general contacted the FCC.