INTERPOL's Operation Jackal IV arrests 58 people, identifies 263 suspects, and disrupts fraud and laundering networks across ...
Critical flaws in WPMU DEV, Avada, TranslatePress, Pods, and GiveWP can enable admin takeover or remote code execution.
Microsoft says TerminalFix uses fake Cloudflare CAPTCHAs to trigger PowerShell and deploy a reverse-tunnel backdoor for internal network access.
Attackers chain two PaperCut NG and MF flaws for unauthenticated remote code execution, with limited exploitation seen in two ...
U.S. Treasury sanctions Iran-linked cyber actors under Operation Economic Outcast, targeting MOIS-linked hackers tied to U.S.
Aikido finds Claude Opus 4.6 bypassed a seven-day booking limit in 9 of 10 OpenClaw runs, with two runs canceling another ...
Berlin confirms an extortion attempt after data theft from its state network, while the scope of the exfiltrated data remains ...
CISA adds CVE-2026-60004 to KEV amid active Gitea RCE exploitation; a separate reported attack deployed a miner-like dropper.
GoCaracal gave operators remote shell access and browser data theft during a June 2026 intrusion at a Venezuelan ...
CISA adds six exploited flaws to KEV, including a NetScaler bug tied to web shells and 36 exploitation attempts in 12 days.
AnonyMousKIT uses AI voice agents posing as Apple Support to request passcodes, Apple ID credentials, and live 2FA codes from ...
Two Unitree G1 EDU vulnerabilities enable separate root RCE chains, including a BLE path; fixed firmware versions remain ...