Fire Ant compromises Cisco IOS XR routers and TACACS servers to capture traffic, harvest credentials, and suppress defensive ...
DoJ corrected its QTFY statement, saying several U.S. agencies were targets rather than confirmed victims of the China-linked ...
Critical flaws in WPMU DEV, Avada, TranslatePress, Pods, and GiveWP can enable admin takeover or remote code execution.
Attackers chain two PaperCut NG and MF flaws for unauthenticated remote code execution, with limited exploitation seen in two ...
Android 17 adds OS-wide ECH, local network permissions, default certificate transparency, and carrier-controlled 2G blocking.
CISA adds six exploited flaws to KEV, including a NetScaler bug tied to web shells and 36 exploitation attempts in 12 days.
INTERPOL's Operation Jackal IV arrests 58 people, identifies 263 suspects, and disrupts fraud and laundering networks across ...
Berlin confirms an extortion attempt after data theft from its state network, while the scope of the exfiltrated data remains ...
GoCaracal gave operators remote shell access and browser data theft during a June 2026 intrusion at a Venezuelan ...
Aikido finds Claude Opus 4.6 bypassed a seven-day booking limit in 9 of 10 OpenClaw runs, with two runs canceling another ...
U.S. Treasury sanctions Iran-linked cyber actors under Operation Economic Outcast, targeting MOIS-linked hackers tied to U.S.
CISA adds actively exploited CVE-2026-21962 to KEV; the Oracle flaw can expose or alter critical data via unauthenticated ...