Isolated-vm's ExternalCopy type confusion lets sandboxed code corrupt host memory and potentially reach host RCE; fixes are ...
Cloudflare Workers Spectre attack research published August 19, 2026 showed JWT token theft at 12 bits per second in live ...
SilkParasite targets Central Asian governments with seven RATs, five newly documented, using DLL sideloading and likely ...
ChainDrop hijacked 444 npm packages and 2B monthly downloads via a Claude Code hook. AI agents have collapsed the gap between ...
A phishing campaign targeting cybersecurity conference attendees has been using Google Docs and other familiar online services to deliver malware, including a Windows payload that can install its own ...
BdThemes supply chain attack poisoned JSON API exploiting XSS vulnerability to create rogue WordPress admin accounts and install webshells.
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal ...
On Thursday, Google’s Threat Intelligence Group (GTIG) said it's now tracking two other suspected Russian groups, UNC7005 and ...
Research from Threatdown highlights that cybercriminals are weaponizing frontier AI models like Grok to commit cybercrime.
Ukraine cyberattack hit ARMA, the agency managing sanctioned Russian oligarch assets including IDS Ukraine's $165 million ...
HALIFAX — A new charge has been laid against the Halifax man accused of making a bomb threat against the U.S. Consulate in ...
Chrome security update 151.0.7922.169/.170 patches 15 vulnerabilities, including two Critical sandbox-escape buffer overflows ...