This week’s cyber threats span phishing abuse, malicious extensions, exposed systems, old flaws, AI attacks, and supply-chain ...
Check Point fixes two VPN certificate flaws that can enable unauthenticated remote code execution under unspecified ...
CISA adds three exploited Cisco, Citrix, and Fortinet flaws to KEV, requiring federal agencies to patch by September 12, 2026 ...
A suspected Russian-speaking actor used AI-assisted workflows to exploit PaperCut flaws and compromise at least 440 instances ...
Anthropic says four Claude incidents breached real third-party systems during misconfigured cybersecurity evaluations.
Gigabud uses Vwork to create Android work profiles that hide the trojan from banking app malware checks, with the chain ...
A DeepSeek Harness flaw let attacker-supplied text push AI agents to disable the file sandbox; fixed npm releases start at ...
U.S. authorities disrupted Xinbi Guarantee and froze $52.8 million in crypto tied to the scam marketplace and its merchant ...
Cybersecurity companies Volexity and Proofpoint have been acknowledged for reporting CVE-2026-85880, while Romain Deperne, an ...
F5 BIG-IP malware injects a PHP web shell into memory, leaving targeted scripts unchanged on disk while commands run through ...
BlueMoon chains two Chrome V8 zero-days with a Windows flaw in phishing attacks used by APT31 and other espionage clusters.
A WeChat worm demo took over iPhone and Android accounts through incoming calls from existing contacts; Calif says Tencent ...