This week’s cyber threats span phishing abuse, malicious extensions, exposed systems, old flaws, AI attacks, and supply-chain ...
Check Point fixes two VPN certificate flaws that can enable unauthenticated remote code execution under unspecified ...
A suspected Russian-speaking actor used AI-assisted workflows to exploit PaperCut flaws and compromise at least 440 instances ...
Gigabud uses Vwork to create Android work profiles that hide the trojan from banking app malware checks, with the chain ...
CISA adds three exploited Cisco, Citrix, and Fortinet flaws to KEV, requiring federal agencies to patch by September 12, 2026 ...
Anthropic says four Claude incidents breached real third-party systems during misconfigured cybersecurity evaluations.
U.S. authorities disrupted Xinbi Guarantee and froze $52.8 million in crypto tied to the scam marketplace and its merchant ...
BlueMoon chains two Chrome V8 zero-days with a Windows flaw in phishing attacks used by APT31 and other espionage clusters.
Infostealer logs expose replayable AI session tokens and API keys that can bypass login controls and enable unauthorized account access.
A DeepSeek Harness flaw let attacker-supplied text push AI agents to disable the file sandbox; fixed npm releases start at ...
Alby warns a critical Hub flaw could let attackers take over internet-exposed wallets; versions 1.19.0 and later are not affected.
Panel patched CVE-2026-67401, which lets a hosting account with mail privileges create files anywhere and run code as root.