Unbound 1.26.1 fixes a critical DNSSEC heap overflow that malicious zones can trigger, with possible remote code execution.
FamousSparrow deploys SparroWocky against government entities across Latin America, enabling command execution and file ...
Cisco ISE CVE-2026-76460 is under active exploitation; successful exploitation may yield root command execution.
Gyazo says a breach exposed 23.62 million user records and 490 million image metadata records, including IDs used to build ...
Researchers showed one browser extension could hijack AI features in five Chromium products; some demos could access files, ...
Issabel Framework flaw CVE-2026-89026 is under active exploitation and can enable unauthenticated OS command execution via a ...
U.S. authorities seized two NightmareStresser domains tied to a DDoS-for-hire service used in hundreds of thousands of attacks and attempts.
Attackers are exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells and gain remote code ...
Mandiant says an attacker hijacked an active AI coding session, stole GitHub OAuth tokens, and spread Shai-Hulud across about ...
N0va phishing abuses legitimate authentication flows to capture access and refresh tokens and establish SSO access to ...
BambooToken uses MQTT for C2 across Windows and Linux, with a dozen compromised entities detected in Asia and South America.
WSO2 API Manager JWT bypass faces active exploitation attempts using forged tokens with administrator privileges.