Researchers showed one browser extension could hijack AI features in five Chromium products; some demos could access files, ...
Issabel Framework flaw CVE-2026-89026 is under active exploitation and can enable unauthenticated OS command execution via a ...
Mandiant says an attacker hijacked an active AI coding session, stole GitHub OAuth tokens, and spread Shai-Hulud across about ...
N0va phishing abuses legitimate authentication flows to capture access and refresh tokens and establish SSO access to ...
Attackers are exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells and gain remote code ...
WSO2 API Manager JWT bypass faces active exploitation attempts using forged tokens with administrator privileges.
BambooToken uses MQTT for C2 across Windows and Linux, with a dozen compromised entities detected in Asia and South America.
U.S., U.K., and Dutch agencies say Iran’s intelligence service uses Telegram-controlled Windows malware to spy on dissidents ...
UTA0560 exploited a Chrome-Windows zero-day chain against NGOs to deploy GRIMWEDGE; APT31 used the same chain to install LONGTALE.
Microsoft details a million-email CEO fraud campaign and passkey-themed attacks that compromised cloud accounts and enabled ...
A report links OpenAI agents to a RubyGems campaign that abused RubyDoc for RCE and published more than 2,000 packages in May ...
AI-related SOC alerts rose 685% from February to June 2026, with 94.1% classified as noise and 5.8% as genuine security risks ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results