WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under ...
SilkParasite targets Central Asian governments with seven RATs, five newly documented, using DLL sideloading and likely ...
SaaS platforms, CRM and ERP systems, and collaboration tools have made the browser the primary gateway, and often the central ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Research from Threatdown highlights that cybercriminals are weaponizing frontier AI models like Grok to commit cybercrime.
Ukraine cyberattack hit ARMA, the agency managing sanctioned Russian oligarch assets including IDS Ukraine's $165 million ...
Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach.
Seqrite warns that attackers are using SVG files to hide malicious JavaScript and phishing redirects, creating a new security ...
In the worst-case scenario, attackers can execute malicious code and completely compromise n8n servers. Even though there are ...
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create ...
BdThemes supply chain attack poisoned JSON API exploiting XSS vulnerability to create rogue WordPress admin accounts and install webshells.
Reports from Cisco Talos and CrowdStrike provide real-world insights into how AI is evolving attackers’ tradecraft and ...