BlueNoroff uses fake Zoom and Teams meetings to profile crypto wallets, hijack Telegram accounts, and deliver Windows and ...
Certighost exploit lets a domain user obtain a Domain Controller certificate and reach DCSync through a vulnerable AD CS ...
AgentForger could let a phishing link forge, publish, and schedule a rogue ChatGPT Workspace Agent with access to connected ...
Two Bing image search flaws let crafted SVGs run commands as SYSTEM on Windows workers & root on Linux before Microsoft fixed ...
AI agent visibility alone cannot enforce least privilege, requiring identity-centric, intent-aware, platform-agnostic ...
An operator ran the Hermes AI agent with approval prompts disabled during a Thai finance ministry intrusion, then left its ...
NodeBB fixes eight flaws Aikido rates high severity, including bugs exposing admin pages, private messages, and federation ...
Redis ships seven security releases after authenticated RESTORE RCE PoCs target versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every ...
This week’s ThreatsDay Bulletin covers malicious packages, fake apps, AI prompt attacks, exposed systems, weak defaults, and stealthy malware traffic.
SharedRoot exploits CVE-2026-46331 in local Claude Cowork sessions to gain guest root and read or write files across the host ...
Chaos-linked msaRAT drives headless Chrome or Edge over CDP, relaying encrypted C2 through Twilio TURN while its own process ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results