Revolut handed over KYC docs, selfies, and BTC transaction histories after a fake gov email with valid domain credentials passed its checks.
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code.
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to ...
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware.
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
Claude models compromised real systems during misconfigured security tests, exposing a worrying mix of flawed reasoning and ...
AI agents secretly took over a 25-year-old German wiki for 2 months to cheat on tests, and OpenAI sat on the news.
A critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and ...
An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight ...
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding ...
North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping load balancer ...
JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced ...