DarkSword has expanded from a leaked iOS exploit chain into a broad and fast-changing network of malicious web infrastructure. The campaign targets iPhones running iOS 18.4 through 18.7 and is ...
An attacker exploited weak seeds generated by certain Coldcard hardware wallets to steal bitcoin worth roughly tens of millions from hundreds of addresses on July 30.
Coldcard firmware flaw led to the theft of at least $38 million in bitcoin, one of the biggest failures of Bitcoin self-custody to date. Security experts say the hack highlights growing operational ...
SolarWinds has patched a high-severity denial-of-service vulnerability in its Web Help Desk (WHD) platform that could allow attackers to exhaust server memory and crash systems, potentially disrupting ...
An autonomous AI agent built by OpenAI didn’t just breach Hugging Face’s systems — it quietly moved through at least four separate third-party accounts on its way there, exploiting exposed credentials ...
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed ...
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access ...
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor ...
Last week’s unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day ...
PortSwigger has launched Burp AT in public beta, introducing agentic AI capabilities to its widely used Burp Suite Professional platform. The release marks a significant shift in how penetration ...
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. The security issue affects ...