A suspected Russian-speaking actor used AI-assisted workflows to exploit PaperCut flaws and compromise at least 440 instances ...
Check Point fixes two VPN certificate flaws that can enable unauthenticated remote code execution under unspecified ...
CISA adds three exploited Cisco, Citrix, and Fortinet flaws to KEV, requiring federal agencies to patch by September 12, 2026 ...
BlueMoon chains two Chrome V8 zero-days with a Windows flaw in phishing attacks used by APT31 and other espionage clusters.
A DeepSeek Harness flaw let attacker-supplied text push AI agents to disable the file sandbox; fixed npm releases start at ...
U.S. authorities disrupted Xinbi Guarantee and froze $52.8 million in crypto tied to the scam marketplace and its merchant ...
Gigabud uses Vwork to create Android work profiles that hide the trojan from banking app malware checks, with the chain ...
Anthropic says four Claude incidents breached real third-party systems during misconfigured cybersecurity evaluations.
F5 BIG-IP malware injects a PHP web shell into memory, leaving targeted scripts unchanged on disk while commands run through ...
Alby warns a critical Hub flaw could let attackers take over internet-exposed wallets; versions 1.19.0 and later are not affected.
Cybersecurity companies Volexity and Proofpoint have been acknowledged for reporting CVE-2026-85880, while Romain Deperne, an ...
A financially motivated actor used an autonomous multi-agent framework to compromise thousands of third-party credentials in ...